Sample viewer

vx.netlux.org/Virus.DOS.Immortal.1894

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:17.179729858Z 48 PC: 12c35 | Get DOS version
2018-12-17T22:50:17.181918013Z 29 PC: 12c4a | Reserved
2018-12-17T22:50:17.199111357Z 82 PC: 9f4a0 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:50:17.215328139Z 53 PC: 9f4ac | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:50:17.216826308Z 37 PC: 9f4b5 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:50:17.219066846Z 53 PC: 9f4ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:17.220602324Z 29 PC: 9f53b | Reserved
2018-12-17T22:50:17.222256066Z 37 PC: 9f542 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:50:17.225191641Z 37 PC: 9fa86 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:17.226778334Z 42 PC: 9f677 | Get date 0x9f677: mov word ptr cs:[0x331], ss
0x9f67c: mov word ptr cs:[0x336], sp
0x9f681: mov sp, cs
0x9f683: mov ss, sp
0x9f685: mov sp, 0x801
0x9f688: pushf
0x9f689: push ax
0x9f68a: push bx
0x9f68b: push es
0x9f68c: push bp
0x9f68d: mov ax, word ptr cs:[0x782]
0x9f691: cmp ah, 0x11
0x9f694: jne 0x9f6c3
0x9f696: cmp al, 0xff
0x9f698: je 0x9f6c1
0x9f69a: mov ah, 0x2f
0x9f69c: call 0x9fa7f
0x9f69f: cmp byte ptr es:[bx], 0xff
0x9f6a3: jne 0x9f6a8
0x9f6a5: add bx, 7
2018-12-17T22:50:17.229977241Z 9 PC: 9f677 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T22:50:17.249422501Z 76 PC: 9f677 | Terminate with return code (Return code = '36')