Sample viewer

vx.netlux.org/Virus.DOS.Elf.3400

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:08.855051988Z 13 PC: 13e22 | Disk reset
2018-12-17T22:45:08.856862691Z 53 PC: 13e5d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:08.858737861Z 42 PC: 13f42 | Get date 0x13f42: sub bx, si
0x13f44: mov dx, cx
0x13f46: cld
0x13f47: and bl, ah
0x13f49: sbb dx, word ptr es:[0x9bcb]
0x13f4e: rol cx, 1
0x13f50: or bp, word ptr ss:[0x510c]
0x13f55: mov bp, 0x80db
0x13f58: mov si, 0x25c3
0x13f5b: test di, sp
0x13f5d: sub word ptr cs:[bp - 0x6a2f], 0xc474
0x13f64: test byte ptr ss:[0x7b72], ch
0x13f69: xor ah, byte ptr [0x80ac]
0x13f6d: adc di, si
0x13f6f: call 0x13f80
0x13f72: lea di, word ptr [0xba17]
0x13f76: mov ax, 0x7a9b
0x13f79: lea di, word ptr [0x59b0]
0x13f7d: sbb ch, dh
0x13f7f: mov cx, 0xe1c3
2018-12-17T22:45:08.86277205Z 202 PC: 1400c | UNKNOWN!
2018-12-17T22:45:08.863516882Z 51 PC: 14013 | Get or set Ctrl-Break
2018-12-17T22:45:08.864862008Z 53 PC: 146f8 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:08.866091254Z 37 PC: 14705 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:08.867779396Z 48 PC: 14722 | Get DOS version
2018-12-17T22:45:08.87009843Z 37 PC: 14729 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:08.871731834Z 98 PC: 140e5 | Get current PSP
2018-12-17T22:45:08.872854535Z 76 PC: 13be3 | Terminate with return code (Return code = '0')