Sample viewer

vx.netlux.org/Virus.DOS.Lyceum.1950

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:35.556537058Z 171 PC: 12f4f | UNKNOWN!
2018-12-17T21:58:35.557885696Z 44 PC: 12f81 | Get time 0x12f81: cmp dl, 0x32
0x12f84: jb 0x12f89
0x12f86: add si, 0x16
0x12f89: mov cx, 0x16
0x12f8c: rep movsb byte ptr es:[di], byte ptr [si]
0x12f8e: pop si
0x12f8f: push es
0x12f90: pop ds
0x12f91: mov word ptr [0x7c4], 0
0x12f97: mov word ptr [0x7ce], 0
0x12f9d: mov byte ptr [0x7d0], 0
0x12fa2: mov ax, 0x3508
0x12fa5: int 0x21
0x12fa7: mov word ptr [0x7b4], bx
0x12fab: mov word ptr [0x7b6], es
0x12faf: mov al, 9
0x12fb1: int 0x21
0x12fb3: mov word ptr [0x7b8], bx
0x12fb7: mov word ptr [0x7ba], es
0x12fbb: mov al, 0x13
2018-12-17T21:58:35.559943424Z 53 PC: 12fa7 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:58:35.56097246Z 53 PC: 12fb3 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:58:35.56312155Z 53 PC: 12fbf | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:58:35.565265446Z 53 PC: 12fcb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:58:35.567309555Z 37 PC: 12fdb | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:58:35.569836784Z 37 PC: 12fe2 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:58:35.570980412Z 37 PC: 12fe9 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:58:35.572021202Z 37 PC: 12ff0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')