Sample viewer

vx.netlux.org/Virus.DOS.Lokjaw.1052

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:19.977023957Z 44 PC: 12ab8 | Get time 0x12ab8: cmp ax, 0xdcd
0x12abb: je 0x12b18
0x12abd: mov ax, cs
0x12abf: dec ax
0x12ac0: mov ds, ax
0x12ac2: cmp byte ptr [0], 0x5a
0x12ac7: jne 0x12b10
0x12ac9: mov ax, word ptr [3]
0x12acc: sub ax, 0x100
0x12acf: mov word ptr [3], ax
0x12ad2: mov bx, ax
0x12ad4: mov ax, es
0x12ad6: add ax, bx
0x12ad8: mov es, ax
0x12ada: mov cx, 0x41c
0x12add: mov ax, ds
0x12adf: inc ax
0x12ae0: mov ds, ax
0x12ae2: lea si, word ptr [bp + 0x106]
0x12ae6: mov di, 0x100
2018-12-17T21:55:19.979733115Z 53 PC: 12afa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:19.981792011Z 37 PC: 12b0f | Set interrupt vector (Interrupt = '33' AKA 'Random read')