Sample viewer

vx.netlux.org/Virus.DOS.Emmie.2823.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:26.143557504Z 42 PC: 13656 | Get date 0x13656: mov byte ptr [bp + 0x997], 0
0x1365b: cmp dh, byte ptr [bp + 0x985]
0x1365f: jne 0x1366c
0x13661: cmp cx, word ptr [bp + 0x986]
0x13665: jne 0x1366c
0x13667: mov byte ptr [bp + 0x997], 1
0x1366c: mov byte ptr [bp + 0x985], dh
0x13670: mov word ptr [bp + 0x986], cx
0x13674: mov byte ptr [bp + 0x984], dl
0x13678: xor bx, bx
0x1367a: mov ax, 0xface
0x1367d: int 0x21
0x1367f: cmp ax, 0xcefa
0x13682: jne 0x1368c
0x13684: cmp bx, 0x10
0x13687: jge 0x136a6
0x13689: call 0x13828
0x1368c: mov ax, 0x2c00
0x1368f: int 0x13
0x13691: mov ax, 0xffa5
2018-12-17T22:20:26.146488006Z 250 PC: 1367f | UNKNOWN!
2018-12-17T22:20:26.14804577Z 53 PC: 9e8ed | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:26.149192088Z 53 PC: 9e8fb | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:20:26.151013166Z 53 PC: 9e909 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:20:26.152279122Z 53 PC: 9e917 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:20:26.153425409Z 53 PC: 9e925 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:20:26.155658088Z 53 PC: 9e933 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:20:26.159205009Z 53 PC: 9ead6 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.160504126Z 37 PC: 9eaf4 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.16257509Z 25 PC: 9eb04 | Get default drive
2018-12-17T22:20:26.16379596Z 37 PC: 9eb13 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.164898251Z 53 PC: 9e9f6 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.166648757Z 37 PC: 9ea14 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.16878775Z 37 PC: 9ea36 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.170018169Z 53 PC: 9eb93 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.171398137Z 37 PC: 9ebab | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.173482839Z 37 PC: 9ebce | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:26.17459944Z 37 PC: 9ed7e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:26.175713974Z 37 PC: 9ed7e | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:20:26.177554519Z 37 PC: 9ed7e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:20:26.179465701Z 37 PC: 9ed7e | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:20:26.181027179Z 53 PC: 9ed7e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:20:26.183166015Z 37 PC: 9ed7e | Set interrupt vector (Interrupt = '9' AKA 'Display string')