Sample viewer

vx.netlux.org/Virus.DOS.Foma.1900

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:08.538771722Z 42 PC: 13187 | Get date 0x13187: mov word ptr cs:[si + 0x2f4], dx
0x1318c: mov word ptr cs:[si + 0x2f6], cx
0x13191: mov ax, 0xfe54
0x13194: int 0x21
0x13196: cmp ax, 0x4d5a
0x13199: je 0x131df
0x1319b: mov ah, 0x49
0x1319d: int 0x21
0x1319f: jb 0x131df
0x131a1: mov ah, 0x48
0x131a3: mov bx, 0xffff
0x131a6: int 0x21
0x131a8: sub bx, 0x77
0x131ab: nop
0x131ac: jb 0x131df
0x131ae: mov cx, es
0x131b0: add cx, bx
0x131b2: mov ah, 0x4a
0x131b4: int 0x21
0x131b6: mov bx, 0x77
2018-12-17T22:20:08.542643714Z 254 PC: 13196 | UNKNOWN!
2018-12-17T22:20:08.549616363Z 73 PC: 1319f | Release memory
2018-12-17T22:20:08.551687218Z 72 PC: 131a8 | Allocate memory
2018-12-17T22:20:08.554166972Z 74 PC: 131b6 | Reallocate memory
2018-12-17T22:20:08.556546628Z 74 PC: 131c4 | Reallocate memory
2018-12-17T22:20:08.559195587Z 9 PC: 12a4e | Display string (String= 'Test New Shtamm Program ')
2018-12-17T22:20:08.56448119Z 76 PC: 12a53 | Terminate with return code (Return code = '0')