Sample viewer

vx.netlux.org/Virus.DOS.SMVB.1023

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:06:45.010972139Z 53 PC: 12dc6 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:06:45.01311376Z 53 PC: 12dd4 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:06:45.014409609Z 37 PC: 12de5 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:06:45.015641349Z 42 PC: 12d23 | Get date 0x12d23: cmp byte ptr cs:[0x3dd], 0x20
0x12d29: je 0x12d32
0x12d2b: cmp byte ptr cs:[0x3dd], dl
0x12d30: jne 0x12d63
0x12d32: cmp byte ptr cs:[0x3dc], 0xd
0x12d38: je 0x12d41
0x12d3a: cmp byte ptr cs:[0x3dc], dh
0x12d3f: jne 0x12d63
0x12d41: cmp word ptr cs:[0x3da], 0xbb8
0x12d48: je 0x12d51
0x12d4a: cmp word ptr cs:[0x3da], cx
0x12d4f: jne 0x12d63
0x12d51: cmp byte ptr cs:[0x3de], 8
0x12d57: je 0x12d64
0x12d59: cmp byte ptr cs:[0x3de], al
0x12d5e: jne 0x12d63
0x12d60: jmp 0x12d64
0x12d62: nop
0x12d63: ret
0x12d64: call 0x22aba
2018-12-17T22:06:45.018433393Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:45.019659655Z 221 PC: 12b36 | UNKNOWN!
2018-12-17T22:06:45.020484859Z 37 PC: 12b44 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:45.021931251Z 74 PC: 12af6 | Reallocate memory
2018-12-17T22:06:45.023810584Z 75 PC: 12ba2 | Execute program
2018-12-17T22:06:45.040480012Z 42 PC: 12af6 | Get date 0x12af6: retf 2
0x12af9: mov ax, 0x4d2
0x12afc: iret
0x12afd: mov ax, es
0x12aff: mov ds, ax
0x12b01: mov si, 0x4f8
0x12b04: mov di, 0x100
0x12b07: mov cx, 0xfe00
0x12b0a: sub cx, 0x4f8
0x12b0e: cld
0x12b0f: rep movsb byte ptr es:[di], byte ptr [si]
0x12b11: mov word ptr cs:[0x188], 0x100
0x12b18: mov word ptr cs:[0x18a], es
0x12b1d: push es
0x12b1e: pop ss
0x12b1f: ljmp ptr cs:[0x188]
0x12b24: mov ah, 0x35
0x12b26: mov al, 0x21
0x12b28: int 0x21
0x12b2a: mov word ptr [0x17e], bx
2018-12-17T22:06:45.042976734Z 53 PC: 12af6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:45.057414884Z 9 PC: 12af6 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')
2018-12-17T22:06:45.063550964Z 49 PC: 12af6 | Terminate and stay resident (Return code = '0' | Memory size = '80')