Sample viewer

vx.netlux.org/Virus.DOS.Jackel.654

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:28.782658779Z 44 PC: 12e2f | Get time 0x12e2f: mov al, ch
0x12e31: cwde
0x12e32: cmp ax, 0x10
0x12e35: jge 0x12e3a
0x12e37: jmp 0x12e9b
0x12e39: nop
0x12e3a: cli
0x12e3b: mov dx, 2
0x12e3e: mov bp, 0x40
0x12e41: mov si, 0x1000
0x12e44: mov di, 0x2000
0x12e47: mov al, 0xb6
0x12e49: out 0x43, al
0x12e4b: mov bx, si
0x12e4d: mov ax, bx
0x12e4f: out 0x42, al
0x12e51: mov al, ah
0x12e53: out 0x42, al
0x12e55: in al, 0x61
0x12e57: or al, 3
2018-12-17T22:41:28.785459468Z 160 PC: 12eb0 | UNKNOWN!
2018-12-17T22:41:28.78724905Z 53 PC: 12ef2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:28.788999247Z 37 PC: 12f07 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:28.790825497Z 9 PC: 12e26 | Display string (String= ' Phalcon/Skism COM host file - 1000 bytes (c) 1995, Night Crawler ')