Sample viewer

vx.netlux.org/Virus.DOS.Emmie.2620

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:22.290075278Z 42 PC: 13b5c | Get date 0x13b5c: mov byte ptr [bp - 0x64], 0
0x13b60: cmp cx, 0x7bc
0x13b64: je 0x13b74
0x13b66: cmp dh, byte ptr [bp - 0x76]
0x13b69: jne 0x13b74
0x13b6b: cmp cx, word ptr [bp - 0x75]
0x13b6e: jne 0x13b74
0x13b70: mov byte ptr [bp - 0x64], 1
0x13b74: mov byte ptr [bp - 0x76], dh
0x13b77: mov word ptr [bp - 0x75], cx
0x13b7a: xor bx, bx
0x13b7c: mov ax, 0xface
0x13b7f: int 0x21
0x13b81: cmp ax, 0xcefa
0x13b84: jne 0x13b8e
0x13b86: cmp bx, 0xb
0x13b89: jge 0x13ba8
0x13b8b: call 0x23aad
0x13b8e: mov ax, 0x2c00
0x13b91: int 0x13
2018-12-17T21:57:22.30581963Z 250 PC: 13b81 | UNKNOWN!
2018-12-17T21:57:22.307767844Z 53 PC: 9f426 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:22.309137069Z 53 PC: 9f435 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:57:22.310882413Z 53 PC: 9f444 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T21:57:22.31832127Z 53 PC: 9f5f8 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.319907557Z 37 PC: 9f616 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.321868732Z 25 PC: 9f626 | Get default drive
2018-12-17T21:57:22.323166242Z 37 PC: 9f635 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.324333498Z 53 PC: 9f51f | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.325578334Z 37 PC: 9f53d | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.327943797Z 37 PC: 9f55f | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.329379814Z 53 PC: 9f6b5 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.330426221Z 37 PC: 9f6cd | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.332625522Z 37 PC: 9f6f0 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.333714676Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:22.334788873Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T21:57:22.336784375Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T21:57:22.337754013Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T21:57:22.338812733Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T21:57:22.341066423Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.342611212Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:57:22.344141275Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:57:22.34668789Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '9' AKA 'Display string')