Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Pisello.1024.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:24.873392049Z 53 PC: 14501 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:24.875214595Z 42 PC: 14834 | Get date 0x14834: ret
0x14835: int 0x24
0x14837: call 0x247f7
0x1483a: pop es
0x1483b: pop ds
0x1483c: sbb al, 2
0x1483e: push cs
0x1483f: nop
0x14840: xchg ax, dx
0x14841: add byte ptr [di], ch
0x14843: adc al, bl
0x14845: add ax, 8
0x14848: push ax
0x14849: lea ax, word ptr [bp - 0x104]
0x1484d: push ax
0x1484e: call 0x2172f
0x14851: add sp, 6
0x14854: mov si, word ptr [bp - 0x104]
0x14858: and si, 0xff
0x1485c: mov byte ptr [bp + si - 0x103], 0
2018-12-17T23:11:24.877412466Z 74 PC: 1457d | Reallocate memory
2018-12-17T23:11:24.878733579Z 72 PC: 14584 | Allocate memory
2018-12-17T23:11:24.88141598Z 72 PC: 13231 | Allocate memory
2018-12-17T23:11:24.882992601Z 75 PC: 1326b | Execute program
2018-12-17T23:11:24.898195778Z 48 PC: 13848 | Get DOS version
2018-12-17T23:11:24.900525073Z 74 PC: 138bf | Reallocate memory
2018-12-17T23:11:24.902305277Z 72 PC: 14b01 | Allocate memory
2018-12-17T23:11:24.904888646Z 74 PC: 14ab1 | Reallocate memory
2018-12-17T23:11:24.907812567Z 48 PC: 13b48 | Get DOS version
2018-12-17T23:11:24.909458636Z 53 PC: 13949 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:24.91080675Z 37 PC: 1395b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:24.912140286Z 68 PC: 139e7 | I/O control for devices (Set for = 'INDOWS\TEMP ')
2018-12-17T23:11:24.913871928Z 68 PC: 139e7 | I/O control for devices (Set for = 'DIRCMD=')
2018-12-17T23:11:24.915244331Z 68 PC: 139e7 | I/O control for devices
2018-12-17T23:11:24.916680851Z 68 PC: 139e7 | I/O control for devices
2018-12-17T23:11:24.918861181Z 68 PC: 139e7 | I/O control for devices
2018-12-17T23:11:24.92043447Z 54 PC: 14b47 | Get free disk space
2018-12-17T23:11:24.931489754Z 64 PC: 147ca | Write file or device (Write 28 bytes on handle 1)
2018-12-17T23:11:24.938255366Z 64 PC: 147ca | Write file or device (Write 25 bytes on handle 1)
2018-12-17T23:11:24.944482718Z 64 PC: 147ca | Write file or device (Write 25 bytes on handle 1)
2018-12-17T23:11:24.95184314Z 64 PC: 147ca | Write file or device (Write 20 bytes on handle 1)
2018-12-17T23:11:24.958060799Z 37 PC: 13aa3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:24.959443237Z 76 PC: 13a88 | Terminate with return code (Return code = '19')
2018-12-17T23:11:24.962615184Z 37 PC: 132a0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:24.96458699Z 77 PC: 132a4 | Get program return code
2018-12-17T23:11:24.965657076Z 49 PC: 132ab | Terminate and stay resident (Return code = '19' | Memory size = '64')