Sample viewer

vx.netlux.org/Virus.DOS.Aztech.1200

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:23.53881346Z 48 PC: 13c51 | Get DOS version
2018-12-17T22:41:23.566493269Z 44 PC: 13c61 | Get time 0x13c61: or dh, dh
0x13c63: jne 0x13c68
0x13c65: jmp 0x13ff8
0x13c68: mov ax, 0xf000
0x13c6b: mov dx, word ptr [0x476]
0x13c6f: int 0x2f
0x13c71: inc cx
0x13c72: je 0x13c40
0x13c74: or al, al
0x13c76: jne 0x13c40
0x13c78: mov ax, 0x5801
0x13c7b: mov bx, 2
0x13c7e: int 0x21
0x13c80: mov ah, 0x48
0x13c82: mov bx, 0x90
0x13c85: int 0x21
0x13c87: jae 0x13cb4
0x13c89: mov bx, word ptr es:[2]
0x13c8e: sub bx, 0x91
0x13c92: mov dx, cs
2018-12-17T22:41:23.570072836Z 88 PC: 13c80 | case 0xGet or set allocation strateg:
2018-12-17T22:41:23.571869934Z 72 PC: 13c87 | Allocate memory
2018-12-17T22:41:23.57823379Z 74 PC: 13cad | Reallocate memory
2018-12-17T22:41:23.579893265Z 72 PC: 13cb4 | Allocate memory
2018-12-17T22:41:23.581426052Z 53 PC: 13cc3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:23.582601277Z 53 PC: 13ccf | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:41:23.596315034Z 37 PC: 13cf2 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:23.597724825Z 37 PC: 13cf9 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:41:23.599693048Z 88 PC: 13d00 | case 0xGet or set allocation strateg:
2018-12-17T22:41:23.60204518Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T22:41:23.609219544Z 76 PC: 12a61 | Terminate with return code (Return code = '0')