Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Pinniz.1536.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:23.615234265Z 74 PC: 12cff | Reallocate memory
2018-12-17T22:32:23.617780905Z 72 PC: 12d06 | Allocate memory
2018-12-17T22:32:23.619722668Z 42 PC: 134c2 | Get date 0x134c2: ret
0x134c3: pop es
0x134c4: add word ptr cs:[0x3f], 1
0x134ca: cli
0x134cb: push ax
0x134cc: xor ax, ax
0x134ce: mov es, ax
0x134d0: mov ax, word ptr cs:[0x36]
0x134d4: mov word ptr es:[0x84], ax
0x134d8: mov ax, word ptr cs:[0x38]
0x134dc: mov word ptr es:[0x86], ax
0x134e0: pop ax
0x134e1: call 0x2319d
0x134e4: cmp byte ptr cs:[0x34c], 7
0x134ea: je 0x134e1
0x134ec: int 0x21
0x134ee: call 0x2317a
0x134f1: cli
0x134f2: xor ax, ax
0x134f4: mov es, ax
2018-12-17T22:32:23.622208049Z 72 PC: 13246 | Allocate memory
2018-12-17T22:32:23.623994538Z 75 PC: 13280 | Execute program
2018-12-17T22:32:23.652581707Z 76 PC: 13934 | Terminate with return code (Return code = '0')
2018-12-17T22:32:23.656290373Z 53 PC: 13294 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:23.658040776Z 37 PC: 132ab | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:23.660730897Z 77 PC: 132af | Get program return code
2018-12-17T22:32:23.668266933Z 49 PC: 132b6 | Terminate and stay resident (Return code = '0' | Memory size = '96')