Sample viewer

vx.netlux.org/Virus.DOS.WoodGoblin.2413

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:11.763853838Z 98 PC: 133ce | Get current PSP
2018-12-17T22:51:11.765858994Z 82 PC: 135b5 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:51:11.767448141Z 42 PC: 135e9 | Get date 0x135e9: cmp byte ptr cs:[si + 0x97f], 1
0x135ef: jne 0x1360f
0x135f1: mov ah, 1
0x135f3: mov byte ptr cs:[si + 0x97f], 0
0x135f9: mov word ptr cs:[si + 0xd6], 0x184
0x13600: pushf
0x13601: push 0x300
0x13604: popf
0x13605: lcall ptr [0x4c]
0x13609: cmp byte ptr cs:[si + 0x97f], 1
0x1360f: pop word ptr [4]
0x13613: pop word ptr [6]
0x13617: popaw
0x13618: ret
0x13619: mov ax, ds
0x1361b: cmp ax, word ptr cs:[di + 0x43]
0x1361f: jne 0x13625
0x13621: mov word ptr cs:[di + 0x41], si
0x13625: ret
0x13626: mov ax, ds
2018-12-17T22:51:11.771456687Z 9 PC: 13276 | Display string (Could not find end pointer)
2018-12-17T22:51:11.777299577Z 48 PC: 1327f | Get DOS version
2018-12-17T22:51:11.779339755Z 61 PC: 1334c | Open file (Filename = '')
2018-12-17T22:51:11.7861092Z 93 PC: 132ee | File sharing functions
2018-12-17T22:51:11.788016708Z 9 PC: 13276 | Display string (String= 'Size change=09EFh/02543d. ')
2018-12-17T22:51:11.792419251Z 76 PC: 132d3 | Terminate with return code (Return code = '1')