Sample viewer

vx.netlux.org/Virus.DOS.Arale.1526

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:22.290341253Z 153 PC: 12bbe | UNKNOWN!
2018-12-17T22:49:22.291635044Z 42 PC: 12c5c | Get date 0x12c5c: mov si, 0x65
0x12c5f: lodsw ax, word ptr [si]
0x12c60: cmp ax, dx
0x12c62: je 0x12c97
0x12c64: add si, 0xc
0x12c67: lodsw ax, word ptr [si]
0x12c68: cmp ax, dx
0x12c6a: je 0x12c97
0x12c6c: add si, 0xe
0x12c6f: lodsw ax, word ptr [si]
0x12c70: cmp ax, dx
0x12c72: je 0x12c97
0x12c74: add si, 0xb
0x12c77: lodsw ax, word ptr [si]
0x12c78: cmp ax, dx
0x12c7a: je 0x12c97
0x12c7c: add si, 0xd
0x12c7f: lodsw ax, word ptr [si]
0x12c80: cmp ax, dx
0x12c82: je 0x12c97
2018-12-17T22:49:22.295930875Z 74 PC: 12d16 | Reallocate memory
2018-12-17T22:49:22.297861091Z 53 PC: 12d1b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:22.299417706Z 37 PC: 12d2d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:22.302044802Z 75 PC: 12d62 | Execute program
2018-12-17T22:49:22.317596591Z 76 PC: 13268 | Terminate with return code (Return code = '0')
2018-12-17T22:49:22.321053536Z 73 PC: 12d76 | Release memory
2018-12-17T22:49:22.324626469Z 49 PC: 12d83 | Terminate and stay resident (Return code = '0' | Memory size = '124')