Sample viewer

vx.netlux.org/Virus.DOS.ABC.2378

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:16.684998659Z 42 PC: 16d44 | Get date 0x16d44: mov al, 1
0x16d46: mov byte ptr cs:[0x51], al
0x16d4a: cmp dl, 0xf
0x16d4d: jb 0x16d52
0x16d4f: jmp 0x16d58
0x16d51: nop
0x16d52: mov al, 0
0x16d54: mov byte ptr cs:[0x51], al
0x16d58: mov ax, 0x3521
0x16d5b: int 0x21
0x16d5d: mov ax, es
0x16d5f: mov word ptr cs:[0x37], ax
0x16d63: mov word ptr cs:[0x35], bx
0x16d68: mov ax, 0x3516
0x16d6b: int 0x21
0x16d6d: mov ax, es
0x16d6f: mov word ptr cs:[0x4a], ax
0x16d73: mov word ptr cs:[0x48], bx
0x16d78: mov ax, 0x351c
0x16d7b: int 0x21
2018-12-17T22:47:16.687979804Z 53 PC: 16d5d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:16.689421944Z 53 PC: 16d6d | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:47:16.690855104Z 53 PC: 16d7d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:47:16.692778631Z 48 PC: 16da7 | Get DOS version
2018-12-17T22:47:16.693994696Z 37 PC: 16e0e | Set interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:47:16.695322969Z 37 PC: 16e16 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:47:16.697619255Z 37 PC: 16e1e | Set interrupt vector (Interrupt = '96' AKA 'Qualify filename')
2018-12-17T22:47:16.698862807Z 37 PC: 16e2f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:16.70036109Z 76 PC: 12c17 | Terminate with return code (Return code = '0')