Sample viewer

vx.netlux.org/Virus.DOS.Yankee.Flip.2167

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:06.165773744Z 161 PC: 13760 | UNKNOWN!
2018-12-17T22:34:06.167409183Z 53 PC: 137e3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:06.168606398Z 37 PC: 137f3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:06.170660368Z 42 PC: 137f7 | Get date 0x137f7: cmp cx, word ptr [0x2d]
0x137fb: ja 0x1380d
0x137fd: jb 0x13812
0x137ff: cmp dh, byte ptr [0x2f]
0x13803: ja 0x1380d
0x13805: jb 0x13812
0x13807: cmp dl, byte ptr [0x30]
0x1380b: jb 0x13812
0x1380d: call 0x236de
0x13810: je 0x13817
0x13812: sti
0x13813: pop ax
0x13814: pop ds
0x13815: pop es
0x13816: retf
0x13817: mov ax, 0x40
0x1381a: mov es, ax
0x1381c: mov ah, byte ptr es:[0x6c]
0x13821: mov al, 0xb6
0x13823: mov word ptr [0x2fb], ax
2018-12-17T22:34:06.173596996Z 53 PC: 1382b | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:34:06.175785075Z 53 PC: 13838 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:34:06.177086158Z 53 PC: 13845 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:34:06.178520796Z 37 PC: 13855 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:34:06.180686318Z 37 PC: 1385d | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:34:06.182541087Z 37 PC: 13865 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:34:06.184450494Z 9 PC: 12fac | Display string (Could not find end pointer)
2018-12-17T22:34:06.192228175Z 76 PC: 12fb0 | Terminate with return code (Return code = '36')