Sample viewer

vx.netlux.org/Virus.DOS.SVC.3241

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:36.611162177Z 146 PC: 17c14 | UNKNOWN!
2018-12-17T22:18:36.613125302Z 42 PC: 17c4c | Get date 0x17c4c: mov word ptr cs:[si + 0xc4c], cx
0x17c51: mov byte ptr cs:[si + 0xc4e], dh
0x17c56: mov byte ptr cs:[si + 0xc4f], dl
0x17c5b: mov ah, 0
0x17c5d: int 0x1a
0x17c5f: mov word ptr cs:[si + 0xc50], dx
0x17c64: pop bx
0x17c65: pop ax
0x17c66: pop cx
0x17c67: pop dx
0x17c68: pop es
0x17c69: pop ds
0x17c6a: push es
0x17c6b: xor bx, bx
0x17c6d: mov ds, bx
0x17c6f: les bx, ptr [0x84]
0x17c73: mov word ptr cs:[si + 0xc8d], bx
0x17c78: mov word ptr cs:[si + 0xc8f], es
0x17c7d: les bx, ptr [0x20]
0x17c81: mov word ptr cs:[si + 0xc85], bx
2018-12-17T22:18:36.615320062Z 73 PC: 17ca3 | Release memory
2018-12-17T22:18:36.616545808Z 72 PC: 17caf | Allocate memory
2018-12-17T22:18:36.619141062Z 74 PC: 17cc5 | Reallocate memory
2018-12-17T22:18:36.620750015Z 74 PC: 17cde | Reallocate memory
2018-12-17T22:18:36.628420054Z 48 PC: 18097 | Get DOS version
2018-12-17T22:18:36.630827019Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:36.63436725Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:36.636042866Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')