Sample viewer

vx.netlux.org/Virus.DOS.TPE.Duwende.1872

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:25.018685291Z 255 PC: 12aff | UNKNOWN!
2018-12-17T23:11:25.021157563Z 74 PC: 12b1a | Reallocate memory
2018-12-17T23:11:25.023500256Z 72 PC: 12b22 | Allocate memory
2018-12-17T23:11:25.025812731Z 44 PC: 9fb4e | Get time 0x9fb4e: in al, 0x40
0x9fb50: mov ah, al
0x9fb52: in al, 0x40
0x9fb54: xor ax, cx
0x9fb56: xor dx, ax
0x9fb58: jmp 0x9fb77
0x9fb5a: push dx
0x9fb5b: push cx
0x9fb5c: push bx
0x9fb5d: in al, 0x40
0x9fb5f: add ax, 0x1072
0x9fb62: mov dx, 0x3060
0x9fb65: mov cx, 7
0x9fb68: shl ax, 1
0x9fb6a: rcl dx, 1
0x9fb6c: mov bl, al
0x9fb6e: xor bl, dh
0x9fb70: jns 0x9fb74
0x9fb72: inc al
0x9fb74: loop 0x9fb68
2018-12-17T23:11:25.029360673Z 53 PC: 9f4c9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:25.032378249Z 37 PC: 9f4d8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:25.034437919Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T23:11:25.05180407Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')