Sample viewer

vx.netlux.org/Virus.DOS.Iwag.4183

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:44.017394489Z 240 PC: 13c70 | UNKNOWN!
2018-12-17T22:42:44.0196728Z 74 PC: 12ad0 | Reallocate memory
2018-12-17T22:42:44.021123066Z 42 PC: 12ad4 | Get date 0x12ad4: mov byte ptr cs:[0xecc], 0
0x12ada: nop
0x12adb: cmp cx, 0x7cd
0x12adf: je 0x12b0a
0x12ae1: cmp cx, 0x7ce
0x12ae5: jne 0x12aec
0x12ae7: cmp dh, 2
0x12aea: jbe 0x12b0a
0x12aec: mov byte ptr cs:[0xecc], 1
0x12af2: nop
0x12af3: mov byte ptr cs:[0xed5], al
0x12af7: mov byte ptr cs:[0xed4], dl
0x12afc: mov byte ptr cs:[0xed6], dh
0x12b01: mov ah, 0x2c
0x12b03: int 0x21
0x12b05: mov byte ptr cs:[0xed7], ch
0x12b0a: mov byte ptr cs:[0xecd], 0
0x12b10: nop
0x12b11: mov ax, 0x1500
0x12b14: xor bx, bx
2018-12-17T22:42:44.02359331Z 44 PC: 12b05 | Get time 0x12b05: mov byte ptr cs:[0xed7], ch
0x12b0a: mov byte ptr cs:[0xecd], 0
0x12b10: nop
0x12b11: mov ax, 0x1500
0x12b14: xor bx, bx
0x12b16: int 0x2f
0x12b18: cmp bx, 0
0x12b1b: je 0x12b2e
0x12b1d: mov byte ptr cs:[0xecd], 1
0x12b23: nop
0x12b24: mov word ptr cs:[0xece], cx
0x12b29: mov word ptr cs:[0xf7d], cs
0x12b2e: mov word ptr cs:[0xeaa], 0
0x12b35: mov word ptr cs:[0xe71], 0
0x12b3c: mov ax, 0
0x12b3f: mov es, ax
0x12b41: mov al, byte ptr es:[0x46c]
0x12b45: mov byte ptr cs:[0xed3], al
0x12b49: mov byte ptr cs:[0xecb], 0
0x12b4f: nop
2018-12-17T22:42:44.026338891Z 48 PC: 12b54 | Get DOS version
2018-12-17T22:42:44.028225813Z 73 PC: 12c1f | Release memory
2018-12-17T22:42:44.029872462Z 47 PC: 12d70 | Get disk transfer address
2018-12-17T22:42:44.031035459Z 26 PC: 12d88 | Set disk transfer address
2018-12-17T22:42:44.03227894Z 67 PC: 12dbe | Get or set file attributes
2018-12-17T22:42:44.040390717Z 61 PC: 12de7 | Open file (Filename = '[X��')
2018-12-17T22:42:44.048361187Z 63 PC: 12e04 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:42:44.05203091Z 66 PC: 12e26 | Move file pointer
2018-12-17T22:42:44.053883707Z 63 PC: 12e36 | Read file or device (Read 22 bytes on handle 5)
2018-12-17T22:42:44.056718806Z 66 PC: 12e62 | Move file pointer
2018-12-17T22:42:44.070293619Z 63 PC: 12e71 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:42:44.081012823Z 62 PC: 13175 | Close file
2018-12-17T22:42:44.083148116Z 67 PC: 1318e | Get or set file attributes
2018-12-17T22:42:44.103708774Z 26 PC: 131b7 | Set disk transfer address
2018-12-17T22:42:44.105114613Z 75 PC: 12c4d | Execute program
2018-12-17T22:42:44.125269314Z 9 PC: 141dc | Display string (Could not find end pointer)
2018-12-17T22:42:44.132856607Z 76 PC: 141e1 | Terminate with return code (Return code = '0')
2018-12-17T22:42:44.136600334Z 49 PC: 12c76 | Terminate and stay resident (Return code = '0' | Memory size = '310')