Sample viewer

vx.netlux.org/Virus.DOS.Sunset.1081

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:21.97668928Z 154 PC: 17e57 | UNKNOWN!
2018-12-17T22:34:21.978236593Z 42 PC: 17ecc | Get date 0x17ecc: cmp word ptr cs:[bp + 0xee], dx
0x17ed1: jne 0x17ed6
0x17ed3: call 0x18183
0x17ed6: pop es
0x17ed7: pop ds
0x17ed8: jmp 0x17edb
0x17edb: mov ax, 0x6eb
0x17ede: mov word ptr [0x100], ax
0x17ee1: mov al, 0x90
0x17ee3: mov byte ptr [0x102], al
0x17ee6: push 0x100
0x17ee9: ret
0x17eea: mov ax, es
0x17eec: add ax, 0x10
0x17eef: add word ptr cs:[bp + 0xf2], ax
0x17ef4: add word ptr cs:[bp + 0xf6], ax
0x17ef9: mov ss, word ptr cs:[bp + 0xf6]
0x17efe: mov sp, word ptr cs:[bp + 0xf4]
0x17f03: ljmp ptr cs:[bp + 0xf0]
0x17f08: cmp ax, 0x9aff
2018-12-17T22:34:21.980522975Z 9 PC: 12a51 | Display string (String= 'This is a mid COM sample!')
2018-12-17T22:34:21.98266239Z 76 PC: 12a56 | Terminate with return code (Return code = '0')
2018-12-17T22:34:21.985929753Z 72 PC: 9fb79 | Allocate memory
2018-12-17T22:34:21.987638383Z 82 PC: 9fb80 | Get DOS internal pointers (SYSVARS)