Sample viewer

vx.netlux.org/Virus.DOS.LAVI.836.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:30.260374552Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-17T22:46:30.263434729Z 185 PC: 12adb | UNKNOWN!
2018-12-17T22:46:30.268124958Z 74 PC: 12b05 | Reallocate memory
2018-12-17T22:46:30.270301456Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:30.272258922Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:30.275107011Z 75 PC: 12b6b | Execute program
2018-12-17T22:46:30.287687389Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-17T22:46:30.290737457Z 76 PC: 132a4 | Terminate with return code (Return code = '1')
2018-12-17T22:46:30.295125769Z 73 PC: 12b77 | Release memory
2018-12-17T22:46:30.298932679Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:09.34817337Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:09.358804776Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:09.360451533Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:09.361776624Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:09.370998036Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:09.372266119Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:09.383520162Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:09.387246761Z 76 PC: 132a4 | Terminate with return code (Return code = '2')
2018-12-25T12:22:09.390152056Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:09.391609709Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:09.527513038Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:09.530644876Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:09.532089225Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:09.533785606Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:09.535852607Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:09.538007695Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:09.549796245Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:09.552360376Z 76 PC: 132a4 | Terminate with return code (Return code = '6')
2018-12-25T12:22:09.566962214Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:09.568179431Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":25,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.011759026Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.015075889Z 9 PC: 12b94 | Display string (String= 'Poner aca el texto deseado')
2018-12-25T12:22:10.017547137Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.01881553Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.021084083Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.023277399Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.024781344Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.038305544Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.040608747Z 9 PC: 133f4 | Display string (String= 'Poner aca el texto deseado')
2018-12-25T12:22:10.044384563Z 76 PC: 132a4 | Terminate with return code (Return code = '36')
2018-12-25T12:22:10.056448417Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.059497454Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.159104632Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.160978984Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.162375056Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.16350431Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.164547489Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.166090108Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.173409399Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.175002884Z 76 PC: 132a4 | Terminate with return code (Return code = '2')
2018-12-25T12:22:10.177786231Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.178887381Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.172651522Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.175480514Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.176427796Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.177556269Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.178522983Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.180097083Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.191088264Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.194081078Z 76 PC: 132a4 | Terminate with return code (Return code = '6')
2018-12-25T12:22:10.198228666Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.200219188Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":25,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.22695085Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.230277162Z 9 PC: 12b94 | Display string (String= 'Poner aca el texto deseado')
2018-12-25T12:22:10.236626674Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.237984803Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.239520013Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.241415257Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.2427049Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.257049323Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.259779337Z 9 PC: 133f4 | Display string (String= 'Poner aca el texto deseado')
2018-12-25T12:22:10.264872099Z 76 PC: 132a4 | Terminate with return code (Return code = '36')
2018-12-25T12:22:10.268018633Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.270339897Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.223218441Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.226153511Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.228843392Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.230427533Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.231854377Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.234198802Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.247077354Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.250691034Z 76 PC: 132a4 | Terminate with return code (Return code = '2')
2018-12-25T12:22:10.255208603Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.257108147Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.441054517Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.445615708Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.447545777Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.449623794Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.451286909Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.456979238Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.469484872Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.472076592Z 76 PC: 132a4 | Terminate with return code (Return code = '6')
2018-12-25T12:22:10.483412663Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.484905079Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":25,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8906,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:10.496588717Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x19
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:22:10.499345623Z 9 PC: 12b94 | Display string (String= 'Poner aca el texto deseado')
2018-12-25T12:22:10.5024965Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:22:10.50360916Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:22:10.504923991Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.506689301Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:10.508328443Z 75 PC: 12b6b | Execute program
2018-12-25T12:22:10.521014455Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x19
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:22:10.524000852Z 9 PC: 133f4 | Display string (String= 'Poner aca el texto deseado')
2018-12-25T12:22:10.528052769Z 76 PC: 132a4 | Terminate with return code (Return code = '36')
2018-12-25T12:22:10.531797593Z 73 PC: 12b77 | Release memory
2018-12-25T12:22:10.534258877Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')