Sample viewer

vx.netlux.org/Virus.DOS.Acurev.666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:52.703833246Z 78 PC: 12c09 | Find first file
2018-12-17T22:43:52.708789947Z 59 PC: 12c09 | Change current directory
2018-12-17T22:43:52.714755276Z 42 PC: 12c09 | Get date 0x12c09: ret
0x12c0a: or cl, byte ptr [di]
0x12c0c: inc cx
0x12c0d: arpl word ptr [di + 0x72], si
0x12c10: jbe 0x12c33
0x12c13: jbe 0x12c46
0x12c15: cmp byte ptr cs:[bx + si], ah
0x12c18: arpl word ptr [bx + 0x64], bp
0x12c1b: and byte ptr fs:[bp + si + 0x79], ah
0x12c20: and byte ptr [bp + di + 0x69], cl
0x12c23: insb byte ptr es:[di], dx
0x12c24: dec dx
0x12c25: popaw
0x12c26: outsb dx, byte ptr gs:[si]
0x12c2a: and byte ptr [bx + 0x66], ch
0x12c2d: and byte ptr [si + 0x68], dh
0x12c30: and byte ptr gs:[bp + di + 0x6f], al
0x12c34: bound si, dword ptr gs:[bp + si + 0x65]
0x12c39: popaw
0x12c3a: imul sp, word ptr [di + 0x72], 0x73
2018-12-17T22:43:52.71730819Z 42 PC: 12c09 | Get date 0x12c09: ret
0x12c0a: or cl, byte ptr [di]
0x12c0c: inc cx
0x12c0d: arpl word ptr [di + 0x72], si
0x12c10: jbe 0x12c33
0x12c13: jbe 0x12c46
0x12c15: cmp byte ptr cs:[bx + si], ah
0x12c18: arpl word ptr [bx + 0x64], bp
0x12c1b: and byte ptr fs:[bp + si + 0x79], ah
0x12c20: and byte ptr [bp + di + 0x69], cl
0x12c23: insb byte ptr es:[di], dx
0x12c24: dec dx
0x12c25: popaw
0x12c26: outsb dx, byte ptr gs:[si]
0x12c2a: and byte ptr [bx + 0x66], ch
0x12c2d: and byte ptr [si + 0x68], dh
0x12c30: and byte ptr gs:[bp + di + 0x6f], al
0x12c34: bound si, dword ptr gs:[bp + si + 0x65]
0x12c39: popaw
0x12c3a: imul sp, word ptr [di + 0x72], 0x73