Sample viewer

vx.netlux.org/Virus.DOS.Life.1472

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:51.714072605Z 44 PC: 12adb | Get time 0x12adb: ret
0x12adc: clc
0x12add: inc ax
0x12ade: sbb word ptr [bx + si], ax
0x12ae0: mov word ptr cs:[bp + 0x130], ds
0x12ae5: xor ax, ax
0x12ae7: mov es, ax
0x12ae9: mov di, 4
0x12aec: cli
0x12aed: cld
0x12aee: stosw word ptr es:[di], ax
0x12aef: stosw word ptr es:[di], ax
0x12af0: add di, 4
0x12af3: stosw word ptr es:[di], ax
0x12af4: stosw word ptr es:[di], ax
0x12af5: sti
0x12af6: sub word ptr cs:[bp + 0x1c8], 0x7182
0x12afd: call 0x12b08
0x12b00: add word ptr cs:[bp + 0x1c8], 0x7182
0x12b07: ret
2018-12-17T22:27:51.740769189Z 25 PC: 12adb | Get default drive
2018-12-17T22:27:51.74285431Z 71 PC: 12adb | Get current directory
2018-12-17T22:27:51.746561002Z 53 PC: 12adb | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:51.748342773Z 37 PC: 12adb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:51.750931285Z 26 PC: 12adb | Set disk transfer address
2018-12-17T22:27:51.752213047Z 78 PC: 12adb | Find first file
2018-12-17T22:27:51.758860106Z 79 PC: 12adb | Find next file
2018-12-17T22:27:51.761924214Z 26 PC: 12adb | Set disk transfer address
2018-12-17T22:27:51.764112497Z 59 PC: 12adb | Change current directory
2018-12-17T22:27:51.769314183Z 78 PC: 12adb | Find first file
2018-12-17T22:27:51.77656155Z 59 PC: 12adb | Change current directory
2018-12-17T22:27:51.778632962Z 42 PC: 12adb | Get date 0x12adb: ret
0x12adc: clc
0x12add: inc ax
0x12ade: sbb word ptr [bx + si], ax
0x12ae0: mov word ptr cs:[bp + 0x130], ds
0x12ae5: xor ax, ax
0x12ae7: mov es, ax
0x12ae9: mov di, 4
0x12aec: cli
0x12aed: cld
0x12aee: stosw word ptr es:[di], ax
0x12aef: stosw word ptr es:[di], ax
0x12af0: add di, 4
0x12af3: stosw word ptr es:[di], ax
0x12af4: stosw word ptr es:[di], ax
0x12af5: sti
0x12af6: sub word ptr cs:[bp + 0x1c8], 0x7182
0x12afd: call 0x12b08
0x12b00: add word ptr cs:[bp + 0x1c8], 0x7182
0x12b07: ret
2018-12-17T22:27:51.781522473Z 37 PC: 12adb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:51.783030163Z 76 PC: 12adb | Terminate with return code (Return code = '0')