Sample viewer

vx.netlux.org/Virus.DOS.WildFire.2222

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:33.225120627Z 11 PC: 13bd4 | Get input status
2018-12-17T22:42:33.22959991Z 42 PC: 13291 | Get date 0x13291: sub cx, word ptr [0x2c0]
0x13295: jg 0x132ac
0x13297: jl 0x132a7
0x13299: sub dh, byte ptr [0x2c2]
0x1329d: jg 0x132b6
0x1329f: jl 0x132a7
0x132a1: sub dl, byte ptr [0x2c3]
0x132a5: ja 0x132c8
0x132a7: mov cx, 0
0x132aa: jmp 0x132df
0x132ac: sub dh, byte ptr [0x2c2]
0x132b0: jae 0x132b6
0x132b2: add dh, 0xc
0x132b5: dec cx
0x132b6: sub dl, byte ptr [0x2c3]
0x132ba: jae 0x132c8
0x132bc: add dl, 0x1e
0x132bf: sub dh, 1
0x132c2: jae 0x132c8
0x132c4: add dh, 0xc
2018-12-17T22:42:33.231893765Z 44 PC: 1313b | Get time 0x1313b: mov dh, 0
0x1313d: add dx, 0x1e
0x13140: mov word ptr [0x2b3], dx
0x13144: mov ax, 0x3508
0x13147: int 0x21
0x13149: mov word ptr [0x19e], bx
0x1314d: mov bx, es
0x1314f: mov word ptr [0x1a0], bx
0x13153: push cs
0x13154: pop es
0x13155: mov ax, 0x2508
0x13158: lea dx, word ptr [0x2db]
0x1315c: int 0x21
0x1315e: mov ax, 0x3521
0x13161: int 0x21
0x13163: mov word ptr [0x1a2], bx
0x13167: mov bx, es
0x13169: mov word ptr [0x1a4], bx
0x1316d: push cs
0x1316e: pop es
2018-12-17T22:42:33.233963168Z 53 PC: 13149 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:33.236422861Z 37 PC: 1315e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:33.238152025Z 53 PC: 13163 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:33.24061947Z 37 PC: 13178 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:33.242854767Z 74 PC: 131a2 | Reallocate memory
2018-12-17T22:42:33.259241361Z 67 PC: 12ec1 | Get or set file attributes
2018-12-17T22:42:33.281847584Z 67 PC: 12ed9 | Get or set file attributes
2018-12-17T22:42:33.318101413Z 61 PC: 12eea | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:42:33.326103393Z 66 PC: 12eff | Move file pointer
2018-12-17T22:42:33.328260501Z 66 PC: 12f22 | Move file pointer
2018-12-17T22:42:33.329834471Z 63 PC: 12f34 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:42:33.333546053Z 62 PC: 130fb | Close file
2018-12-17T22:42:33.335530243Z 67 PC: 1310b | Get or set file attributes
2018-12-17T22:42:33.370836848Z 75 PC: 131fb | Execute program
2018-12-17T22:42:33.387092972Z 9 PC: 149d2 | Display string (Could not find end pointer)
2018-12-17T22:42:33.391470191Z 76 PC: 149d8 | Terminate with return code (Return code = '0')
2018-12-17T22:42:33.39462003Z 73 PC: 13209 | Release memory
2018-12-17T22:42:33.399003856Z 77 PC: 1320e | Get program return code
2018-12-17T22:42:33.40058875Z 49 PC: 1321f | Terminate and stay resident (Return code = '0' | Memory size = '219')