Sample viewer

vx.netlux.org/Virus.DOS.Lokjaw.512

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:23.106440735Z 42 PC: 12b8d | Get date 0x12b8d: cwde
0x12b8e: cmp ax, 5
0x12b91: je 0x12bef
0x12b93: ret
0x12b94: cmp word ptr es:[di - 3], 0x4546
0x12b9a: je 0x12bef
0x12b9c: cmp word ptr es:[di - 3], 0x5852
0x12ba2: je 0x12bef
0x12ba4: cmp word ptr es:[di - 3], 0x504f
0x12baa: jne 0x12bb4
0x12bac: cmp word ptr es:[di - 5], 0x5453
0x12bb2: je 0x12bef
0x12bb4: cmp word ptr es:[di - 3], 0x5641
0x12bba: je 0x12bef
0x12bbc: cmp word ptr es:[di - 3], 0x544f
0x12bc2: jne 0x12bcc
0x12bc4: cmp word ptr es:[di - 5], 0x5250
0x12bca: je 0x12bef
0x12bcc: cmp word ptr es:[di - 3], 0x4e41
0x12bd2: jne 0x12bec
2018-12-17T22:40:23.109009559Z 37 PC: 12a8b | Set interrupt vector (Interrupt = '33' AKA 'Random read')