Sample viewer

vx.netlux.org/Virus.DOS.Emmie.3097

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:08.763624545Z 42 PC: 13aae | Get date 0x13aae: mov byte ptr [bp + 0xab0], 0
0x13ab3: cmp dh, byte ptr [bp + 0xa9e]
0x13ab7: jne 0x13ac4
0x13ab9: cmp cx, word ptr [bp + 0xa9f]
0x13abd: jne 0x13ac4
0x13abf: mov byte ptr [bp + 0xab0], 1
0x13ac4: mov byte ptr [bp + 0xa9e], dh
0x13ac8: mov word ptr [bp + 0xa9f], cx
0x13acc: mov byte ptr [bp + 0xa9d], dl
0x13ad0: xor bx, bx
0x13ad2: mov ax, 0xface
0x13ad5: int 0x21
0x13ad7: cmp ax, 0xcefa
0x13ada: jne 0x13ae4
0x13adc: cmp bx, 0x15
0x13adf: jge 0x13afe
0x13ae1: call 0x13c80
0x13ae4: mov ax, 0x2c00
0x13ae7: int 0x13
0x13ae9: mov ax, 0xffa5
2018-12-17T22:48:08.766775238Z 250 PC: 13ad7 | UNKNOWN!
2018-12-17T22:48:08.768451833Z 53 PC: 9e6df | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:08.769605434Z 53 PC: 9e6ed | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:48:08.771576279Z 53 PC: 9e6fb | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:48:08.773125792Z 53 PC: 9e709 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:48:08.774652193Z 53 PC: 9e717 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:48:08.776979855Z 53 PC: 9e725 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:48:08.778590317Z 53 PC: 9e8c8 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.779847076Z 37 PC: 9e8e6 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.782308143Z 25 PC: 9e8f6 | Get default drive
2018-12-17T22:48:08.783399418Z 37 PC: 9e905 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.784511591Z 53 PC: 9e7e8 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.785906483Z 37 PC: 9e806 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.789635481Z 37 PC: 9e828 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.791735811Z 53 PC: 9e985 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.793731833Z 37 PC: 9e99d | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.799044217Z 37 PC: 9e9c0 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:48:08.800417625Z 37 PC: 9eb71 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:08.801574927Z 37 PC: 9eb71 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:48:08.805055781Z 37 PC: 9eb71 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:48:08.806666211Z 37 PC: 9eb71 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:48:08.808206537Z 53 PC: 9eb71 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:48:08.810453288Z 37 PC: 9eb71 | Set interrupt vector (Interrupt = '9' AKA 'Display string')