Sample viewer

vx.netlux.org/Virus.DOS.Brownie.688

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:14.7757674Z 239 PC: 12a6c | UNKNOWN!
2018-12-17T23:11:14.776610489Z 53 PC: 12a89 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:14.77864684Z 37 PC: 12a92 | Set interrupt vector (Interrupt = '211' AKA 'UNKNOWN!')
2018-12-17T23:11:14.780066068Z 37 PC: 12a9a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:14.781662772Z 42 PC: 9f5e5 | Get date 0x9f5e5: retf 2
0x9f5e8: mov si, dx
0x9f5ea: lodsb al, byte ptr [si]
0x9f5eb: test al, al
0x9f5ed: je 0x9f5e0
0x9f5ef: cmp al, 0x2e
0x9f5f1: jne 0x9f5ea
0x9f5f3: lodsw ax, word ptr [si]
0x9f5f4: and ax, 0xdfdf
0x9f5f7: cmp ax, 0x4f43
0x9f5fa: jne 0x9f5e0
0x9f5fc: lodsb al, byte ptr [si]
0x9f5fd: and al, 0xdf
0x9f5ff: cmp al, 0x4d
0x9f601: jne 0x9f5e0
0x9f603: push bx
0x9f604: push cx
0x9f605: push dx
0x9f606: push di
0x9f607: push ds