Sample viewer

vx.netlux.org/Virus.DOS.Fumble.688

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:12:57.164554864Z 26 PC: 12a84 | Set disk transfer address
2018-12-17T22:12:57.166738248Z 42 PC: 12a94 | Get date 0x12a94: test dl, 1
0x12a97: jne 0x12ab8
0x12a99: mov dx, si
0x12a9b: add dx, 5
0x12a9f: xor cx, cx
0x12aa1: mov ah, 0x4e
0x12aa3: int 0x21
0x12aa5: jb 0x12ab8
0x12aa7: call 0x12ad6
0x12aaa: mov dx, si
0x12aac: add dx, 5
0x12ab0: xor cx, cx
0x12ab2: mov ah, 0x4f
0x12ab4: int 0x21
0x12ab6: jae 0x12aa7
0x12ab8: mov al, byte ptr [si + 0x12]
0x12abb: mov byte ptr [0x100], al
0x12abe: mov ax, word ptr [si + 0x13]
0x12ac1: mov word ptr [0x101], ax
0x12ac4: mov dx, 0x80
2018-12-17T22:12:57.169010893Z 26 PC: 12acb | Set disk transfer address
2018-12-17T22:12:57.170449902Z 74 PC: 12c9a | Reallocate memory
2018-12-17T22:12:57.172230864Z 49 PC: 12a43 | Terminate and stay resident (Return code = '126' | Memory size = '30')