Sample viewer

vx.netlux.org/Virus.DOS.SMEG.Duwende.2513

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:18.493759796Z 44 PC: 12b53 | Get time 0x12b53: shl ch, 1
0x12b55: test cl, 0x3b
0x12b58: and si, ax
0x12b5a: shr ch, cl
0x12b5c: mov cx, 0x3a11
0x12b60: sub si, 0x1b1d
0x12b64: or cl, byte ptr [si + 0x1220]
0x12b68: xor bp, word ptr [0x1f1f]
0x12b6c: xor cx, 0x1f21
0x12b70: test bp, di
0x12b72: rcl cl, 1
0x12b74: sar cx, cl
0x12b76: test byte ptr [bx + 4], cl
0x12b79: mov cl, byte ptr [si + 0x2d17]
0x12b7d: xor ch, ch
0x12b7f: call 0x12b96
0x12b82: call 0x12b9b
0x12b85: rol ch, cl
0x12b87: mov cx, 0x1717
0x12b8b: shr si, 1
2018-12-17T22:24:18.503797882Z 255 PC: 12f45 | UNKNOWN!
2018-12-17T22:24:18.505675402Z 74 PC: 12f60 | Reallocate memory
2018-12-17T22:24:18.508098292Z 72 PC: 12f68 | Allocate memory
2018-12-17T22:24:18.510989676Z 53 PC: 9e796 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:18.513579754Z 37 PC: 9e7a5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:18.516086149Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T22:24:18.532672271Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')