Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Pisello.1536.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:03.650694915Z 42 PC: 12fb8 | Get date 0x12fb8: ret
0x12fb9: pop es
0x12fba: add word ptr cs:[0x44], 1
0x12fc0: cli
0x12fc1: push ax
0x12fc2: xor ax, ax
0x12fc4: mov es, ax
0x12fc6: mov ax, word ptr cs:[0x37]
0x12fca: mov word ptr es:[0x84], ax
0x12fce: mov ax, word ptr cs:[0x39]
0x12fd2: mov word ptr es:[0x86], ax
0x12fd6: pop ax
0x12fd7: call 0x22c83
0x12fda: cmp byte ptr cs:[0x36c], 7
0x12fe0: je 0x12fd7
0x12fe2: int 0x21
0x12fe4: call 0x22c5b
0x12fe7: cli
0x12fe8: xor ax, ax
0x12fea: mov es, ax
2018-12-17T22:49:03.653191656Z 74 PC: 12d0c | Reallocate memory
2018-12-17T22:49:03.655373004Z 72 PC: 12d13 | Allocate memory
2018-12-17T22:49:03.657178818Z 72 PC: 13250 | Allocate memory
2018-12-17T22:49:03.659136927Z 75 PC: 1328a | Execute program
2018-12-17T22:49:03.676104617Z 76 PC: 13934 | Terminate with return code (Return code = '0')
2018-12-17T22:49:03.679647914Z 53 PC: 1329e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:03.681387983Z 37 PC: 132d1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:03.68502177Z 77 PC: 132d5 | Get program return code
2018-12-17T22:49:03.686697178Z 49 PC: 132dc | Terminate and stay resident (Return code = '0' | Memory size = '96')