Sample viewer

vx.netlux.org/Virus.DOS.XPEH.5840

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:42.990684829Z 48 PC: 13937 | Get DOS version
2018-12-17T22:46:42.993691445Z 42 PC: 13585 | Get date 0x13585: cmp cx, word ptr [bp + 4]
0x13588: jb 0x13592
0x1358a: cmp dh, byte ptr [bp + 6]
0x1358d: jb 0x13592
0x1358f: clc
0x13590: jmp 0x13593
0x13592: stc
0x13593: pop dx
0x13594: pop cx
0x13595: pop ax
0x13596: pop bp
0x13597: ret 4
0x1359a: push ax
0x1359b: push cx
0x1359c: push di
0x1359d: push es
0x1359e: cld
0x1359f: mov di, word ptr cs:[0x87]
0x135a4: add di, 0x1f
0x135a7: mov ax, word ptr cs:[0x85]
2018-12-17T22:46:42.996752697Z 193 PC: 13967 | UNKNOWN!
2018-12-17T22:46:43.001774395Z 37 PC: 13b17 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')