Sample viewer

vx.netlux.org/Virus.DOS.TPE.Duwende.1848

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:15.074398442Z 255 PC: 12b0a | UNKNOWN!
2018-12-17T23:08:15.075625734Z 74 PC: 12b25 | Reallocate memory
2018-12-17T23:08:15.077402992Z 72 PC: 12b2d | Allocate memory
2018-12-17T23:08:15.079293937Z 44 PC: 9fb46 | Get time 0x9fb46: in al, 0x40
0x9fb48: mov ah, al
0x9fb4a: in al, 0x40
0x9fb4c: xor ax, cx
0x9fb4e: xor dx, ax
0x9fb50: jmp 0x9fb6f
0x9fb52: push dx
0x9fb53: push cx
0x9fb54: push bx
0x9fb55: in al, 0x40
0x9fb57: add ax, 0xefa6
0x9fb5a: mov dx, 0x9a8f
0x9fb5d: mov cx, 7
0x9fb60: shl ax, 1
0x9fb62: rcl dx, 1
0x9fb64: mov bl, al
0x9fb66: xor bl, dh
0x9fb68: jns 0x9fb6c
0x9fb6a: inc al
0x9fb6c: loop 0x9fb60
2018-12-17T23:08:15.082203213Z 53 PC: 9f4d9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:15.084663154Z 37 PC: 9f4e8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:15.087628862Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T23:08:15.105245525Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')