Sample viewer

vx.netlux.org/Virus.DOS.Selev.2392

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:53.342375181Z 25 PC: 1444b | Get default drive
2018-12-17T22:52:53.344167799Z 53 PC: 14459 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:52:53.345665302Z 44 PC: 14490 | Get time 0x14490: mov word ptr cs:[0x8ce], dx
0x14495: push cs
0x14496: pop ds
0x14497: xor di, di
0x14499: xor si, si
0x1449b: mov cx, 0x958
0x1449e: nop
0x1449f: cld
0x144a0: rep movsb byte ptr es:[di], byte ptr [si]
0x144a2: cli
0x144a3: push 4
0x144a5: pop ds
0x144a6: mov ax, es
0x144a8: mov bx, 0x46
0x144ab: push ax
0x144ac: mov ax, word ptr [bx - 2]
0x144af: mov word ptr es:[0xf9], ax
0x144b3: mov ax, word ptr [bx]
0x144b5: mov word ptr es:[0xfb], ax
0x144b9: pop ax
2018-12-17T22:52:53.348281213Z 158 PC: 144d0 | UNKNOWN!
2018-12-17T22:52:53.349988647Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=00001400h/0000005120d bytes. ')
2018-12-17T22:52:53.354254359Z 76 PC: 12a86 | Terminate with return code (Return code = '36')