Sample viewer

vx.netlux.org/Virus.DOS.TPE.Gambit.2259

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:45.740698363Z 74 PC: 12ac1 | Reallocate memory
2018-12-17T22:44:45.743495043Z 42 PC: 12ac8 | Get date 0x12ac8: shl cx, 1
0x12aca: jb 0x12b19
0x12acc: mov ax, es
0x12ace: dec ax
0x12acf: mov es, ax
0x12ad1: mov bx, word ptr es:[3]
0x12ad6: cmp byte ptr es:[0], 0x5a
0x12adc: je 0x12ae6
0x12ade: mov ax, ds
0x12ae0: add ax, bx
0x12ae2: mov es, ax
0x12ae4: jmp 0x12ad1
0x12ae6: sub bx, 0x13c
0x12aea: mov word ptr es:[3], bx
0x12aef: inc ax
0x12af0: add ax, bx
0x12af2: sub ax, 0x10
0x12af5: mov es, ax
0x12af7: lea si, word ptr [bp + 0x100]
0x12afb: mov di, 0x100
2018-12-17T22:44:45.746736555Z 91 PC: 9ea8c | Create new file
2018-12-17T22:44:45.754730547Z 75 PC: 12b84 | Execute program