Sample viewer

vx.netlux.org/Virus.DOS.Pizelun.3599.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:59.578614293Z 75 PC: 12abf | Execute program
2018-12-17T22:48:59.580603901Z 48 PC: 12ad0 | Get DOS version
2018-12-17T22:48:59.581995597Z 53 PC: 12b38 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:59.58316918Z 82 PC: 12b8a | Get DOS internal pointers (SYSVARS)
2018-12-17T22:48:59.584589148Z 37 PC: 12b9f | Set interrupt vector (Interrupt = '105' AKA 'Get or set media id')
2018-12-17T22:48:59.586177272Z 53 PC: 12ba6 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:48:59.587287152Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:48:59.589092134Z 53 PC: 12bca | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:48:59.59089823Z 82 PC: 12bdb | Get DOS internal pointers (SYSVARS)
2018-12-17T22:48:59.592597619Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:59.594090552Z 42 PC: 12c7c | Get date 0x12c7c: mov word ptr [0xdfc], cx
0x12c80: rol cx, 1
0x12c82: cmp dh, 5
0x12c85: je 0x12c8a
0x12c87: jmp 0x12d26
0x12c8a: mov cx, word ptr [0xdfc]
0x12c8e: cmp cx, 0x7cb
0x12c92: je 0x12ce6
0x12c94: jmp 0x12d26
0x12c97: or ax, 0x500a
0x12c9a: dec cx
0x12c9b: pop dx
0x12c9c: inc bp
0x12c9d: dec sp
0x12c9e: push bp
0x12c9f: dec si
0x12ca0: and byte ptr [bx + di + 0x74], ah
0x12ca3: je 0x12d0e
0x12ca5: jbe 0x12d08
0x12ca7: je 0x12d18