Sample viewer

vx.netlux.org/Virus.DOS.Foma.972

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:56.646014921Z 48 PC: 12ec5 | Get DOS version
2018-12-17T22:14:56.653579476Z 42 PC: 12ecd | Get date 0x12ecd: mov byte ptr cs:[si + 0x48], al
0x12ed1: mov ax, 0xfe54
0x12ed4: int 0x21
0x12ed6: cmp ax, 0x4d5a
0x12ed9: je 0x12f1f
0x12edb: mov ah, 0x49
0x12edd: int 0x21
0x12edf: jb 0x12f1f
0x12ee1: mov ah, 0x48
0x12ee3: mov bx, 0xffff
0x12ee6: int 0x21
0x12ee8: sub bx, 0x3d
0x12eeb: nop
0x12eec: jb 0x12f1f
0x12eee: mov cx, es
0x12ef0: add cx, bx
0x12ef2: mov ah, 0x4a
0x12ef4: int 0x21
0x12ef6: mov bx, 0x3d
0x12ef9: sub word ptr es:[2], bx
2018-12-17T22:14:56.655834729Z 254 PC: 12ed6 | UNKNOWN!
2018-12-17T22:14:56.656659683Z 73 PC: 12edf | Release memory
2018-12-17T22:14:56.65824688Z 72 PC: 12ee8 | Allocate memory
2018-12-17T22:14:56.659861659Z 74 PC: 12ef6 | Reallocate memory
2018-12-17T22:14:56.661059227Z 74 PC: 12f04 | Reallocate memory
2018-12-17T22:14:56.663359897Z 9 PC: 12a4e | Display string (String= 'Test New Shtamm Program ')
2018-12-17T22:14:56.667409748Z 76 PC: 12a53 | Terminate with return code (Return code = '0')