Sample viewer

vx.netlux.org/Virus.DOS.VCL.Rat.665

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:29.244943098Z 42 PC: 12c38 | Get date 0x12c38: cwde
0x12c39: ret
0x12c3a: mov ah, 0x2a
0x12c3c: int 0x21
0x12c3e: xchg ax, cx
0x12c3f: ret
0x12c40: pop bx
0x12c41: push si
0x12c42: inc bx
0x12c43: dec sp
0x12c44: pop bp
0x12c45: add byte ptr [si + 0x68], dl
0x12c48: imul si, word ptr [bp + di + 0x20], 0x7369
0x12c4d: and byte ptr [si + 0x65], ah
0x12c50: imul sp, word ptr fs:[bp + di + 0x61], 0x6574
0x12c56: and byte ptr fs:[si + 0x6f], dh
0x12c5a: and byte ptr [si + 0x68], dh
0x12c5d: and byte ptr gs:[bx + si], ah
0x12c60: and byte ptr [bx + si], ah
0x12c62: add byte ptr [bp + si + 0x49], al
2018-12-17T23:10:29.246704652Z 42 PC: 12c3e | Get date 0x12c3e: xchg ax, cx
0x12c3f: ret
0x12c40: pop bx
0x12c41: push si
0x12c42: inc bx
0x12c43: dec sp
0x12c44: pop bp
0x12c45: add byte ptr [si + 0x68], dl
0x12c48: imul si, word ptr [bp + di + 0x20], 0x7369
0x12c4d: and byte ptr [si + 0x65], ah
0x12c50: imul sp, word ptr fs:[bp + di + 0x61], 0x6574
0x12c56: and byte ptr fs:[si + 0x6f], dh
0x12c5a: and byte ptr [si + 0x68], dh
0x12c5d: and byte ptr gs:[bx + si], ah
0x12c60: and byte ptr [bx + si], ah
0x12c62: add byte ptr [bp + si + 0x49], al
0x12c65: inc di
0x12c66: inc di
0x12c67: inc bp
0x12c68: push bx
2018-12-17T23:10:29.248713642Z 74 PC: 12a85 | Reallocate memory
2018-12-17T23:10:29.24993515Z 81 PC: 12145 | Get current PSP