Sample viewer

vx.netlux.org/Virus.DOS.KeyPress.1266

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:24.183542295Z 48 PC: 13695 | Get DOS version
2018-12-17T22:19:24.186573302Z 98 PC: 136bd | Get current PSP
2018-12-17T22:19:24.188072009Z 42 PC: 136f2 | Get date 0x136f2: and dh, 0
0x136f5: mov word ptr [0x610], dx
0x136f9: mov ax, 0x351c
0x136fc: int 0x21
0x136fe: mov word ptr [0x608], bx
0x13702: mov word ptr [0x60a], es
0x13706: mov ax, 0x3521
0x13709: int 0x21
0x1370b: mov word ptr [0x604], bx
0x1370f: mov word ptr [0x606], es
0x13713: mov dx, 0x4bf
0x13716: mov ax, 0x2521
0x13719: int 0x21
0x1371b: mov ax, 0x251c
0x1371e: mov dx, 0x4cc
0x13721: int 0x21
0x13723: mov si, 0x83
0x13726: call 0x13a55
0x13729: call 0x23614
0x1372c: je 0x13736
2018-12-17T22:19:24.190620945Z 53 PC: 136fe | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:19:24.192685214Z 53 PC: 1370b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:24.19491495Z 37 PC: 1371b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:24.19733Z 37 PC: 13723 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:19:24.199950574Z 9 PC: 12b17 | Display string (String= ' DUMMY v1f - Program xxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxx ')