Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Mosquito.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:34.594031106Z 74 PC: 12ce3 | Reallocate memory
2018-12-17T22:45:34.596058668Z 72 PC: 12cea | Allocate memory
2018-12-17T22:45:34.598056316Z 42 PC: 134ab | Get date 0x134ab: ret
0x134ac: pop es
0x134ad: add word ptr cs:[0x21], 1
0x134b3: cli
0x134b4: push ax
0x134b5: xor ax, ax
0x134b7: mov es, ax
0x134b9: mov ax, word ptr cs:[0x18]
0x134bd: mov word ptr es:[0x84], ax
0x134c1: mov ax, word ptr cs:[0x1a]
0x134c5: mov word ptr es:[0x86], ax
0x134c9: pop ax
0x134ca: call 0x2317f
0x134cd: cmp byte ptr cs:[0x339], 7
0x134d3: je 0x134ca
0x134d5: int 0x21
0x134d7: call 0x2315c
0x134da: cli
0x134db: xor ax, ax
0x134dd: mov es, ax
2018-12-17T22:45:34.600334729Z 72 PC: 1322a | Allocate memory
2018-12-17T22:45:34.601830491Z 75 PC: 13264 | Execute program
2018-12-17T22:45:34.61870026Z 76 PC: 13734 | Terminate with return code (Return code = '0')
2018-12-17T22:45:34.62243222Z 53 PC: 13278 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:34.624016512Z 37 PC: 1328f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:34.625468083Z 77 PC: 13293 | Get program return code
2018-12-17T22:45:34.627488472Z 49 PC: 1329a | Terminate and stay resident (Return code = '0' | Memory size = '64')