Sample viewer

vx.netlux.org/Virus.DOS.Armageddon.1065

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:51.913654013Z 224 PC: 12e6c | UNKNOWN!
2018-12-17T23:08:51.915585654Z 53 PC: 12e7b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:51.917363806Z 37 PC: 12e8b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:51.91907415Z 53 PC: 12e90 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:08:51.921556937Z 37 PC: 12ea0 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:08:51.923086191Z 44 PC: 12ea4 | Get time 0x12ea4: mov byte ptr [0x12c], ch
0x12ea8: mov byte ptr [0x12d], cl
0x12eac: mov byte ptr [0x12e], dh
0x12eb0: mov ax, word ptr cs:[0x2c]
0x12eb4: mov ds, ax
0x12eb6: xor si, si
0x12eb8: mov al, byte ptr [si]
0x12eba: cmp al, 1
0x12ebc: je 0x12ec1
0x12ebe: inc si
0x12ebf: jmp 0x12eb8
0x12ec1: inc si
0x12ec2: inc si
0x12ec3: mov dx, si
0x12ec5: mov ax, cs
0x12ec7: mov es, ax
0x12ec9: mov bx, 0x5a
0x12ecc: mov ah, 0x4a
0x12ece: int 0x21
0x12ed0: mov bx, word ptr cs:[0x81]
2018-12-17T23:08:51.92564486Z 74 PC: 12ed0 | Reallocate memory
2018-12-17T23:08:51.927781285Z 75 PC: 12ef8 | Execute program
2018-12-17T23:08:51.933488161Z 49 PC: 12f0d | Terminate and stay resident (Return code = '0' | Memory size = '83')