Sample viewer

vx.netlux.org/Virus.DOS.Kherson.982

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:12.235484058Z 48 PC: 17bdb | Get DOS version
2018-12-17T22:22:12.23715349Z 9 PC: 17be6 | Display string (String= '')
2018-12-17T22:22:12.238126196Z 42 PC: 17bed | Get date 0x17bed: cli
0x17bee: call 0x17bf1
0x17bf1: pop si
0x17bf2: sub si, 0x2d
0x17bf5: push ds
0x17bf6: push es
0x17bf7: push si
0x17bf8: mov word ptr cs:[si + 0x11], cx
0x17bfc: nop
0x17bfd: xor ax, ax
0x17bff: mov word ptr cs:[si], ax
0x17c02: nop
0x17c03: nop
0x17c04: mov cx, word ptr cs:[si + 2]
0x17c08: nop
0x17c09: mov al, byte ptr cs:[si + 0xc]
0x17c0d: nop
0x17c0e: mov bx, 0x56
0x17c11: sub cx, bx
0x17c13: cld
2018-12-17T22:22:12.239914888Z 250 PC: 17c1f | UNKNOWN!
2018-12-17T22:22:12.241502682Z 9 PC: 17bc0 | Display string (Could not find end pointer)
2018-12-17T22:22:12.244334562Z 76 PC: 17bc4 | Terminate with return code (Return code = '36')