Sample viewer

vx.netlux.org/Virus.DOS.ZGB.2112

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:34.339363843Z 48 PC: 18da5 | Get DOS version
2018-12-17T22:35:34.343247046Z 74 PC: 12b81 | Reallocate memory
2018-12-17T22:35:34.345130759Z 42 PC: 12b9e | Get date 0x12b9e: mov byte ptr cs:[0x13f], 0
0x12ba4: cmp dh, 4
0x12ba7: je 0x12bae
0x12ba9: cmp dh, 8
0x12bac: jne 0x12bb8
0x12bae: cmp dl, 0x11
0x12bb1: jne 0x12bb8
0x12bb3: inc byte ptr cs:[0x13f]
0x12bb8: xor ax, ax
0x12bba: mov es, ax
0x12bbc: push cs
0x12bbd: pop ds
0x12bbe: mov si, 0x16b
0x12bc1: xor di, di
0x12bc3: mov cx, 0x10
0x12bc6: cld
0x12bc7: rep movsb byte ptr es:[di], byte ptr [si]
0x12bc9: in al, 0x21
0x12bcb: and al, 0xfd
0x12bcd: out 0x21, al
2018-12-17T22:35:34.34798962Z 0 PC: 13147 | Program terminate