Sample viewer

vx.netlux.org/Virus.DOS.Foma.1000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:02.353481906Z 48 PC: 12ec9 | Get DOS version
2018-12-17T21:57:02.355109456Z 42 PC: 12ed1 | Get date 0x12ed1: mov byte ptr cs:[si + 0x4a], al
0x12ed5: mov ax, 0xff54
0x12ed8: int 0x21
0x12eda: cmp ax, 0x4d5a
0x12edd: je 0x12f23
0x12edf: mov ah, 0x49
0x12ee1: int 0x21
0x12ee3: jb 0x12f23
0x12ee5: mov ah, 0x48
0x12ee7: mov bx, 0xffff
0x12eea: int 0x21
0x12eec: sub bx, 0x3f
0x12eef: nop
0x12ef0: jb 0x12f23
0x12ef2: mov cx, es
0x12ef4: add cx, bx
0x12ef6: mov ah, 0x4a
0x12ef8: int 0x21
0x12efa: mov bx, 0x3f
0x12efd: sub word ptr es:[2], bx
2018-12-17T21:57:02.357753983Z 255 PC: 12eda | UNKNOWN!
2018-12-17T21:57:02.359025927Z 73 PC: 12ee3 | Release memory
2018-12-17T21:57:02.361062871Z 72 PC: 12eec | Allocate memory
2018-12-17T21:57:02.362813985Z 74 PC: 12efa | Reallocate memory
2018-12-17T21:57:02.365352027Z 74 PC: 12f08 | Reallocate memory
2018-12-17T21:57:02.367198402Z 9 PC: 12a4e | Display string (String= 'Test New Shtamm Program ')
2018-12-17T21:57:02.371343193Z 76 PC: 12a53 | Terminate with return code (Return code = '0')