Sample viewer

vx.netlux.org/Virus.DOS.VLAD.MonAmi.999

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:05.419315743Z 74 PC: 12a53 | Reallocate memory
2018-12-17T21:51:05.421903073Z 44 PC: 9f3c2 | Get time 0x9f3c2: call 0x9f3f5
0x9f3c5: mov ax, 0x3521
0x9f3c8: int 0x21
0x9f3ca: push cs
0x9f3cb: pop ds
0x9f3cc: mov si, 0x88
0x9f3cf: mov word ptr [si + 0x60], bx
0x9f3d2: mov word ptr [si + 0x62], es
0x9f3d5: pop es
0x9f3d6: pop bx
0x9f3d7: xchg dx, si
0x9f3d9: mov ah, 0x25
0x9f3db: int 0x21
0x9f3dd: dec bx
0x9f3de: je 0x9f3f1
0x9f3e0: mov ah, 0x4a
0x9f3e2: int 0x21
0x9f3e4: mov ax, cs
0x9f3e6: dec ax
0x9f3e7: mov ds, ax
2018-12-17T21:51:05.424324672Z 53 PC: 9f3ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:05.425462747Z 37 PC: 9f3dd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:05.427151152Z 74 PC: 9f3e4 | Reallocate memory
2018-12-17T21:51:05.430884975Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T21:51:05.436619128Z 0 PC: 12a89 | Program terminate