Sample viewer

vx.netlux.org/Virus.DOS.TPE.Duwende.1871

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:26.829344987Z 255 PC: 12b47 | UNKNOWN!
2018-12-17T22:38:26.830581627Z 74 PC: 12b62 | Reallocate memory
2018-12-17T22:38:26.831785745Z 72 PC: 12b6a | Allocate memory
2018-12-17T22:38:26.833802725Z 44 PC: 9fb4d | Get time 0x9fb4d: in al, 0x40
0x9fb4f: mov ah, al
0x9fb51: in al, 0x40
0x9fb53: xor ax, cx
0x9fb55: xor dx, ax
0x9fb57: jmp 0x9fb76
0x9fb59: push dx
0x9fb5a: push cx
0x9fb5b: push bx
0x9fb5c: in al, 0x40
0x9fb5e: add ax, 0xba16
0x9fb61: mov dx, 0x766a
0x9fb64: mov cx, 7
0x9fb67: shl ax, 1
0x9fb69: rcl dx, 1
0x9fb6b: mov bl, al
0x9fb6d: xor bl, dh
0x9fb6f: jns 0x9fb73
0x9fb71: inc al
0x9fb73: loop 0x9fb67
2018-12-17T22:38:26.835870842Z 53 PC: 9f4c9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:26.836962478Z 37 PC: 9f4d8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:26.838100132Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T22:38:26.849456677Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')