Sample viewer

vx.netlux.org/Virus.DOS.Cholera.2415

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:15:27.062501931Z 254 PC: 12e0f | UNKNOWN!
2018-12-17T22:15:27.063621216Z 98 PC: 12ec5 | Get current PSP
2018-12-17T22:15:27.064346345Z 53 PC: 12eee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:15:27.065580106Z 37 PC: 12f47 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:15:27.067257111Z 42 PC: 12f4b | Get date 0x12f4b: mov al, dh
0x12f4d: mov byte ptr cs:[bp + 0x1db], al
0x12f52: mov ah, 4
0x12f54: int 0x1a
0x12f56: mov al, byte ptr cs:[bp + 0x1db]
0x12f5b: mov ah, cl
0x12f5d: mov bx, word ptr cs:[bp + 0x1dc]
0x12f62: mov cx, 3
0x12f65: cmp cx, 0
0x12f68: je 0x12f7c
0x12f6a: dec cx
0x12f6b: inc bl
0x12f6d: cmp bl, 0xd
0x12f70: jne 0x12f65
0x12f72: mov bl, 1
0x12f74: inc bh
0x12f76: lea dx, word ptr [bp + 0x415]
0x12f7a: jmp dx
0x12f7c: cmp bx, ax
0x12f7e: jle 0x12f81
2018-12-17T22:15:27.085793215Z 98 PC: 12e1e | Get current PSP
2018-12-17T22:15:27.086611317Z 76 PC: 12b40 | Terminate with return code (Return code = '164')