Sample viewer

vx.netlux.org/Virus.DOS.Rogue.1208

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:34.206627629Z 254 PC: 13da5 | UNKNOWN!
2018-12-17T23:12:34.207724252Z 74 PC: 13de8 | Reallocate memory
2018-12-17T23:12:34.209421267Z 74 PC: 13df0 | Reallocate memory
2018-12-17T23:12:34.210965246Z 72 PC: 13df7 | Allocate memory
2018-12-17T23:12:34.213004759Z 53 PC: 13e0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:34.217789341Z 37 PC: 13e28 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:34.21896402Z 42 PC: 13e2c | Get date 0x13e2c: push cx
0x13e2d: mov cx, 8
0x13e30: shr dx, cl
0x13e32: pop cx
0x13e33: add cx, dx
0x13e35: cmp cx, 0x7d0
0x13e39: jb 0x13e5f
0x13e3b: cmp al, 1
0x13e3d: jne 0x13e5f
0x13e3f: mov ax, 0x3508
0x13e42: int 0x71
0x13e44: sahf
0x13e45: add byte ptr [bx + di], al
0x13e47: inc word ptr [bx + si]
0x13e49: xor bl, byte ptr [bp + si]
0x13e4b: add ax, word ptr [bx + si]
0x13e4d: add byte ptr [si], al
0x13e4f: sbb al, 9
0x13e51: xor bl, byte ptr [bp + si]
0x13e53: xor bl, byte ptr [bp + si]