Sample viewer

vx.netlux.org/Virus.DOS.Emmie.2702

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:37.618758272Z 42 PC: 13bc6 | Get date 0x13bc6: mov byte ptr [bp - 0x6b], 0
0x13bca: cmp cx, 0x7bc
0x13bce: je 0x13bde
0x13bd0: cmp dh, byte ptr [bp - 0x7d]
0x13bd3: jne 0x13bde
0x13bd5: cmp cx, word ptr [bp - 0x7c]
0x13bd8: jne 0x13bde
0x13bda: mov byte ptr [bp - 0x6b], 1
0x13bde: mov byte ptr [bp - 0x7d], dh
0x13be1: mov word ptr [bp - 0x7c], cx
0x13be4: xor bx, bx
0x13be6: mov ax, 0xface
0x13be9: int 0x21
0x13beb: cmp ax, 0xcefa
0x13bee: jne 0x13bf8
0x13bf0: cmp bx, 0xc
0x13bf3: jge 0x13c14
0x13bf5: call 0x23b10
0x13bf8: mov ax, 0x2c00
0x13bfb: int 0x13
2018-12-17T23:10:37.622365153Z 250 PC: 13beb | UNKNOWN!
2018-12-17T23:10:37.624166904Z 53 PC: 9f3e5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:37.625637409Z 53 PC: 9f3f4 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:10:37.627855338Z 53 PC: 9f403 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T23:10:37.629435783Z 53 PC: 9f5be | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.630628451Z 37 PC: 9f5dc | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.63659755Z 25 PC: 9f5ec | Get default drive
2018-12-17T23:10:37.638055516Z 37 PC: 9f5fb | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.639559353Z 53 PC: 9f4de | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.641209677Z 37 PC: 9f4fc | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.64550854Z 37 PC: 9f51e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.646738461Z 53 PC: 9f67b | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.649206029Z 37 PC: 9f693 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.660186732Z 37 PC: 9f6b6 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.661200795Z 37 PC: 9f864 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:37.667031949Z 53 PC: 9f864 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:10:37.668898624Z 37 PC: 9f864 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:10:37.674022594Z 53 PC: 9f864 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T23:10:37.675470371Z 37 PC: 9f864 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T23:10:37.676874073Z 53 PC: 9f864 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.677964941Z 37 PC: 9f864 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:10:37.679238069Z 53 PC: 9f864 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:10:37.683036484Z 37 PC: 9f864 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:10:37.68458004Z 9 PC: 13a3f | Display string (String= 'Virus bate of 4096 Bytes !!!')