Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Mecojoni.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:15.425128791Z 74 PC: 12d10 | Reallocate memory
2018-12-17T23:10:15.427089132Z 72 PC: 12d17 | Allocate memory
2018-12-17T23:10:15.428827131Z 44 PC: 13456 | Get time 0x13456: cmp al, byte ptr cs:[0x3e4]
0x1345b: jne 0x13490
0x1345d: cmp dh, byte ptr cs:[0x3e3]
0x13462: je 0x13490
0x13464: mov dl, 0x80
0x13466: mov dh, 0
0x13468: mov ch, 0
0x1346a: mov cl, 1
0x1346c: mov al, 9
0x1346e: mov ah, 3
0x13470: int 0x13
0x13472: mov dl, 0x80
0x13474: mov dh, 1
0x13476: mov ch, 0
0x13478: mov cl, 1
0x1347a: mov al, 9
0x1347c: mov ah, 3
0x1347e: int 0x13
0x13480: mov dx, 0x341
0x13483: mov ah, 9
2018-12-17T23:10:15.431094931Z 72 PC: 13257 | Allocate memory
2018-12-17T23:10:15.433662693Z 75 PC: 13292 | Execute program
2018-12-17T23:10:15.448556014Z 76 PC: 13934 | Terminate with return code (Return code = '0')
2018-12-17T23:10:15.451954273Z 53 PC: 132a6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:15.453632102Z 37 PC: 132bd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:15.456024706Z 77 PC: 132c1 | Get program return code
2018-12-17T23:10:15.458060114Z 49 PC: 132c8 | Terminate and stay resident (Return code = '0' | Memory size = '96')