Sample viewer

vx.netlux.org/Virus.DOS.Picket.1034

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:43.213190976Z 53 PC: 12af6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:43.21543453Z 42 PC: 12b57 | Get date 0x12b57: cmp ax, 0x1992
0x12b5a: jne 0x12b5f
0x12b5c: jmp 0x12c02
0x12b5f: mov ah, 0x49
0x12b61: int 0x21
0x12b63: jb 0x12b5c
0x12b65: mov ah, 0x48
0x12b67: mov bx, 0xffff
0x12b6a: int 0x21
0x12b6c: sub bx, 0x81
0x12b70: mov cx, es
0x12b72: stc
0x12b73: adc cx, bx
0x12b75: mov ah, 0x4a
0x12b77: int 0x21
0x12b79: mov bx, 0x80
0x12b7c: stc
0x12b7d: sbb word ptr es:[2], bx
0x12b82: mov es, cx
0x12b84: mov ah, 0x4a
2018-12-17T22:24:43.217836881Z 73 PC: 12b63 | Release memory
2018-12-17T22:24:43.219337179Z 72 PC: 12b6c | Allocate memory
2018-12-17T22:24:43.22203814Z 74 PC: 12b79 | Reallocate memory
2018-12-17T22:24:43.224285875Z 74 PC: 12b88 | Reallocate memory
2018-12-17T22:24:43.226296114Z 37 PC: 12aef | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:24:43.227724986Z 53 PC: 12aef | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:24:43.230264939Z 37 PC: 12aef | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')