Sample viewer

vx.netlux.org/Virus.DOS.Corrupted.Gotyou.5052

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:48.847912307Z 94 PC: 12a91 | Network functions
2018-12-17T22:28:48.849832451Z 42 PC: 12a91 | Get date 0x12a91: jb 0x12a9a
0x12a93: mov word ptr [0xc9e], 0
0x12a99: ret
0x12a9a: mov word ptr [0xc9e], ax
0x12a9d: ret
0x12a9e: in al, 0x21
0x12aa0: xor ah, ah
0x12aa2: ret
0x12aa3: push bp
0x12aa4: mov bp, sp
0x12aa6: mov al, byte ptr [bp + 4]
0x12aa9: out 0x21, al
0x12aab: pop bp
0x12aac: ret
0x12aad: mov al, 3
0x12aaf: iret
0x12ab0: push bp
0x12ab1: mov bp, sp
0x12ab3: sub sp, 4
0x12ab6: mov ax, word ptr [bp + 6]
2018-12-17T22:28:48.854666354Z 94 PC: 12a91 | Network functions
2018-12-17T22:28:48.856704885Z 42 PC: 12a91 | Get date 0x12a91: jb 0x12a9a
0x12a93: mov word ptr [0xc9e], 0
0x12a99: ret
0x12a9a: mov word ptr [0xc9e], ax
0x12a9d: ret
0x12a9e: in al, 0x21
0x12aa0: xor ah, ah
0x12aa2: ret
0x12aa3: push bp
0x12aa4: mov bp, sp
0x12aa6: mov al, byte ptr [bp + 4]
0x12aa9: out 0x21, al
0x12aab: pop bp
0x12aac: ret
0x12aad: mov al, 3
0x12aaf: iret
0x12ab0: push bp
0x12ab1: mov bp, sp
0x12ab3: sub sp, 4
0x12ab6: mov ax, word ptr [bp + 6]