Sample viewer

vx.netlux.org/Virus.DOS.Patsy.571

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:54:34.914089233Z 48 PC: 12fb2 | Get DOS version
2018-12-17T21:54:34.915554486Z 53 PC: 12fc0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:54:34.916611348Z 53 PC: 12fcd | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T21:54:34.917516344Z 37 PC: 13006 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:54:34.918837307Z 37 PC: 1300d | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T21:54:34.920133528Z 25 PC: 12f7e | Get default drive
2018-12-17T21:54:34.921138789Z 9 PC: 12a8b | Display string (Could not find end pointer)
2018-12-17T21:54:34.923084221Z 42 PC: 12ad0 | Get date 0x12ad0: push cx
0x12ad1: push dx
0x12ad2: mov ah, al
0x12ad4: mov si, 0x511
0x12ad7: mov dx, 0xba
0x12ada: call 0x12bdf
0x12add: pop ax
0x12ade: push ax
0x12adf: cwde
0x12ae0: push ax
0x12ae1: mov dx, 0xde
0x12ae4: call 0x12c0b
0x12ae7: pop ax
0x12ae8: aam
0x12aea: mov bx, 0x5448
0x12aed: cmp ah, 1
0x12af0: je 0x12b08
0x12af2: cmp al, 3
0x12af4: ja 0x12b08
0x12af6: or al, al
2018-12-17T21:54:34.925039336Z 25 PC: 12b83 | Get default drive
2018-12-17T21:54:34.925898281Z 54 PC: 12b90 | Get free disk space
2018-12-17T21:54:34.931486718Z 76 PC: 12bdf | Terminate with return code (Return code = '0')