Sample viewer

vx.netlux.org/Virus.DOS.BG.1348

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:35.789724705Z 75 PC: 12aaa | Execute program
2018-12-17T22:18:35.792170204Z 53 PC: 12ab7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:35.793606118Z 53 PC: 12ac5 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:18:35.795069508Z 42 PC: 12af6 | Get date 0x12af6: mov byte ptr [0x113], dh
0x12afa: cmp dh, 4
0x12afd: jne 0x12b0b
0x12aff: mov ah, 0x2c
0x12b01: int 0x21
0x12b03: mov word ptr [0x115], cx
0x12b07: mov byte ptr [0x117], dh
0x12b0b: xor si, si
0x12b0d: xor di, di
0x12b0f: mov cx, 0x544
0x12b12: cld
0x12b13: rep movsb byte ptr es:[di], byte ptr [si]
0x12b15: push es
0x12b16: pop ds
0x12b17: mov dx, 0x378
0x12b1a: mov ax, 0x2521
0x12b1d: int 0x21
0x12b1f: mov dx, 0x20b
0x12b22: mov al, 8
0x12b24: int 0x21
2018-12-17T22:18:35.79763751Z 37 PC: 12b1f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:35.799174252Z 37 PC: 12b26 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')