Sample viewer

vx.netlux.org/Virus.DOS.DarkParanoid

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:33.645732593Z 42 PC: 12e2f | Get date 0x12e2f: nop
0x12e30: call 0x1336e
0x12e33: add cx, dx
0x12e35: mov dx, cs
0x12e37: call 0x22de1
0x12e3a: call 0x22dc5
0x12e3d: pushf
0x12e3e: call 0x22e08
0x12e41: popf
0x12e42: jae 0x12e60
0x12e44: mov ax, 0x4aa8
0x12e47: mov bx, 0xffff
0x12e4a: int 0x21
0x12e4c: nop
0x12e4d: mov ah, 0x4a
0x12e4f: sub bx, 0x1d6
0x12e53: int 0x21
0x12e55: nop
0x12e56: call 0x22dc5
0x12e59: jae 0x12e60
2018-12-17T22:25:33.648972933Z 88 PC: 12de6 | case 0xGet or set allocation strateg:
2018-12-17T22:25:33.650379269Z 88 PC: 12def | case 0xGet or set allocation strateg:
2018-12-17T22:25:33.651743118Z 88 PC: 12dfd | case 0xGet or set allocation strateg:
2018-12-17T22:25:33.653510841Z 88 PC: 12e06 | case 0xGet or set allocation strateg:
2018-12-17T22:25:33.655193507Z 80 PC: 12dcc | Set current PSP
2018-12-17T22:25:33.65687947Z 72 PC: 12dd4 | Allocate memory
2018-12-17T22:25:33.662454917Z 80 PC: 12ddd | Set current PSP
2018-12-17T22:25:33.663585151Z 88 PC: 12e12 | case 0xGet or set allocation strateg:
2018-12-17T22:25:33.665359869Z 88 PC: 12e1c | case 0xGet or set allocation strateg:
2018-12-17T22:25:33.667459023Z 74 PC: 12e4c | Reallocate memory
2018-12-17T22:25:33.669045716Z 74 PC: 12e55 | Reallocate memory
2018-12-17T22:25:33.670383536Z 80 PC: 12dcc | Set current PSP
2018-12-17T22:25:33.671645479Z 72 PC: 12dd4 | Allocate memory
2018-12-17T22:25:33.673021529Z 80 PC: 12ddd | Set current PSP
2018-12-17T22:25:33.675825265Z 42 PC: 13641 | Get date 0x13641: nop
0x13642: xor dx, word ptr [0x46e]
0x13646: xor dx, word ptr [0x22]
0x1364a: xor dx, word ptr [0x2354]
0x1364e: mov word ptr [0x1d45], ax
0x13651: popaw
0x13652: ret
0x13653: push ds
0x13654: push cs
0x13655: pop ds
0x13656: mov word ptr [0x1d47], ax
0x13659: push bx
0x1365a: push cx
0x1365b: push dx
0x1365c: mov ax, word ptr [0x1d43]
0x1365f: mov bx, word ptr [0x1d45]
0x13663: mov cx, ax
0x13665: mov dx, 0x8405
0x13668: mul dx
0x1366a: shl cx, 3