Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Bamestra.530

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:54.202942637Z 26 PC: 12a77 | Set disk transfer address
2018-12-17T22:42:54.204619373Z 53 PC: 12a7c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:54.206930693Z 37 PC: 12a8c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:54.208573728Z 78 PC: 12a99 | Find first file
2018-12-17T22:42:54.215457985Z 42 PC: 12abf | Get date 0x12abf: cmp al, 0xff
0x12ac1: jne 0x12ad6
0x12ac3: mov ah, 0x2c
0x12ac5: int 0x21
0x12ac7: cmp ch, 0xff
0x12aca: jne 0x12ad6
0x12acc: cmp cl, 0xff
0x12acf: jne 0x12ad6
0x12ad1: cmp dh, 0xff
0x12ad4: jne 0x12ad6
0x12ad6: mov ax, 0x2524
0x12ad9: lds dx, ptr [bp + 0x342]
0x12add: int 0x21
0x12adf: push cs
0x12ae0: pop ds
0x12ae1: mov ah, 0x1a
0x12ae3: mov dx, 0x80
0x12ae6: pop es
0x12ae7: pop ds
0x12ae8: int 0x21
2018-12-17T22:42:54.218632667Z 37 PC: 12adf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:54.220282297Z 26 PC: 12aea | Set disk transfer address