Sample viewer

vx.netlux.org/Virus.DOS.Nomad.1022

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:57.625207939Z 67 PC: 12c7a | Get or set file attributes
2018-12-17T22:43:57.628428245Z 65 PC: 12c86 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:43:57.63542077Z 44 PC: 12a4f | Get time 0x12a4f: cmp dl, 6
0x12a52: ja 0x12a5c
0x12a54: mov ah, 9
0x12a56: lea dx, word ptr [bp + 0x29a]
0x12a5a: int 0x21
0x12a5c: push 0x6660
0x12a5f: pop ax
0x12a60: int 0x21
0x12a62: cmp bx, 0x5449
0x12a66: je 0x12ab8
0x12a68: pop ds
0x12a69: push ds
0x12a6a: mov ax, ds
0x12a6c: dec ax
0x12a6d: mov ds, ax
0x12a6f: sub word ptr [3], 0x40
0x12a74: sub word ptr [0x12], 0x40
0x12a79: mov ax, 0
0x12a7c: mov ds, ax
0x12a7e: dec word ptr [0x413]
2018-12-17T22:43:57.638150999Z 102 PC: 12a62 | Get or set code page
2018-12-17T22:43:57.641616897Z 76 PC: 12e43 | Terminate with return code (Return code = '0')