Sample viewer

vx.netlux.org/Virus.DOS.Cholera.1497

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:23.613061446Z 254 PC: 12e6a | UNKNOWN!
2018-12-17T22:40:23.614403507Z 98 PC: 12ee6 | Get current PSP
2018-12-17T22:40:23.618236677Z 53 PC: 12f0f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:23.622852957Z 53 PC: 12f1e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:40:23.624705096Z 37 PC: 12f6f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:23.626949141Z 42 PC: 12f73 | Get date 0x12f73: mov al, dh
0x12f75: mov byte ptr cs:[bp + 0x2f0], al
0x12f7a: mov ah, 4
0x12f7c: int 0x1a
0x12f7e: mov al, byte ptr cs:[bp + 0x2f0]
0x12f83: mov ah, cl
0x12f85: mov bx, word ptr cs:[bp + 0x2f1]
0x12f8a: mov cx, 3
0x12f8d: cmp cx, 0
0x12f90: je 0x12fa4
0x12f92: dec cx
0x12f93: inc bl
0x12f95: cmp bl, 0xd
0x12f98: jne 0x12f8d
0x12f9a: mov bl, 1
0x12f9c: inc bh
0x12f9e: lea dx, word ptr [bp + 0x165]
0x12fa2: jmp dx
0x12fa4: cmp bx, ax
0x12fa6: jle 0x12fa9