Sample viewer

vx.netlux.org/Virus.DOS.TS.1418

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:40.544013705Z 48 PC: 12aad | Get DOS version
2018-12-17T22:45:40.545680375Z 88 PC: 12abd | case 0xGet or set allocation strateg:
2018-12-17T22:45:40.547840602Z 88 PC: 12ac3 | case 0xGet or set allocation strateg:
2018-12-17T22:45:40.548997255Z 88 PC: 12ace | case 0xGet or set allocation strateg:
2018-12-17T22:45:40.550972344Z 88 PC: 12aed | case 0xGet or set allocation strateg:
2018-12-17T22:45:40.553725956Z 88 PC: 12af5 | case 0xGet or set allocation strateg:
2018-12-17T22:45:40.555545974Z 74 PC: 12b0c | Reallocate memory
2018-12-17T22:45:40.558461891Z 72 PC: 12b13 | Allocate memory
2018-12-17T22:45:40.562258591Z 42 PC: 12b1c | Get date 0x12b1c: mov byte ptr es:[0x59d], cl
0x12b21: cmp cl, 0xca
0x12b24: ja 0x12b28
0x12b26: xor al, al
0x12b28: push ax
0x12b29: mov word ptr [1], 8
0x12b2f: push si
0x12b30: push cs
0x12b31: pop ds
0x12b32: xor di, di
0x12b34: mov cx, 0x58f
0x12b37: rep movsb byte ptr es:[di], byte ptr [si]
0x12b39: pop si
0x12b3a: mov dx, es
0x12b3c: mov ds, dx
0x12b3e: mov ax, 0x3521
0x12b41: int 0x21
0x12b43: mov word ptr [0x591], bx
0x12b47: mov word ptr [0x593], es
0x12b4b: mov es, dx
2018-12-17T22:45:40.565338336Z 53 PC: 12b43 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:40.567229808Z 37 PC: 12b55 | Set interrupt vector (Interrupt = '33' AKA 'Random read')