Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Bamestra.536

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:49.462199669Z 26 PC: 12a78 | Set disk transfer address
2018-12-17T22:43:49.46359657Z 53 PC: 12a7d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:49.471523705Z 37 PC: 12a8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:49.472953874Z 78 PC: 12a9a | Find first file
2018-12-17T22:43:49.480211673Z 42 PC: 12ac0 | Get date 0x12ac0: cmp al, 0xff
0x12ac2: jne 0x12ad7
0x12ac4: mov ah, 0x2c
0x12ac6: int 0x21
0x12ac8: cmp ch, 0xff
0x12acb: jne 0x12ad7
0x12acd: cmp cl, 0xff
0x12ad0: jne 0x12ad7
0x12ad2: cmp dh, 0xff
0x12ad5: jne 0x12ad7
0x12ad7: mov ax, 0x2524
0x12ada: lds dx, ptr [bp + 0x34a]
0x12ade: int 0x21
0x12ae0: push cs
0x12ae1: pop ds
0x12ae2: mov ah, 0x1a
0x12ae4: mov dx, 0x80
0x12ae7: pop es
0x12ae8: pop ds
0x12ae9: int 0x21
2018-12-17T22:43:49.483823737Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:49.485742251Z 26 PC: 12aeb | Set disk transfer address