Sample viewer

vx.netlux.org/Virus.DOS.Agiplan.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:45.286805365Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:49:45.288874044Z 37 PC: 12e3a | Set interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:49:45.290270197Z 53 PC: 12e3f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:45.291732695Z 37 PC: 12e52 | Set interrupt vector (Interrupt = '126' AKA 'UNKNOWN!')
2018-12-17T22:49:45.29983813Z 37 PC: 12e60 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:45.301362694Z 53 PC: 12e65 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:45.302888679Z 37 PC: 12e78 | Set interrupt vector (Interrupt = '253' AKA 'UNKNOWN!')
2018-12-17T22:49:45.305479222Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:45.307116453Z 42 PC: 12da0 | Get date 0x12da0: cmp cx, word ptr [0x5d0]
0x12da4: ja 0x12dc1
0x12da6: jb 0x12dae
0x12da8: cmp dx, word ptr [0x5d2]
0x12dac: ja 0x12dc1
0x12dae: cmp cx, word ptr [0x5d4]
0x12db2: ja 0x12dc4
0x12db4: jb 0x12dbc
0x12db6: cmp dx, word ptr [0x5d6]
0x12dba: ja 0x12dc4
0x12dbc: mov ax, 0
0x12dbf: jmp 0x12dc7
0x12dc1: or ax, 0xf0
0x12dc4: or ax, 0xf
0x12dc7: mov byte ptr [0x5d8], al
0x12dca: push dx
0x12dcb: push cx
0x12dcc: xor bx, bx
0x12dce: call 0x12de5
0x12dd1: pop cx
2018-12-17T22:49:45.309831219Z 74 PC: 12d58 | Reallocate memory
2018-12-17T22:49:45.311515529Z 72 PC: 12d6f | Allocate memory
2018-12-17T22:49:45.326467227Z 72 PC: 12d74 | Allocate memory