Sample viewer

vx.netlux.org/Virus.DOS.December12.1914

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:57.921278239Z 98 PC: 151cf | Get current PSP
2018-12-17T22:53:57.922886777Z 154 PC: 151d9 | UNKNOWN!
2018-12-17T22:53:57.923965586Z 53 PC: 9ee1e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:57.925183684Z 37 PC: 9ef0f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:57.927036792Z 42 PC: 9ef0f | Get date 0x9ef0f: ret
0x9ef10: push ax
0x9ef11: push bx
0x9ef12: push cx
0x9ef13: push dx
0x9ef14: push si
0x9ef15: push di
0x9ef16: push es
0x9ef17: push ds
0x9ef18: mov word ptr cs:[0x581], dx
0x9ef1d: mov ax, ds
0x9ef1f: mov word ptr cs:[0x583], ax
0x9ef23: call 0x9f15f
0x9ef26: call 0xaee92
0x9ef29: jae 0x9ef2f
0x9ef2b: jmp 0x9f118
0x9ef2e: lcall 0x6ce8:0xc933
0x9ef33: push word ptr [bp + di + 4]
0x9ef36: jmp 0x9f100
0x9ef39: ljmp 0x73ff:0x48e8
2018-12-17T22:53:57.929841472Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=00002968h/0000010600d bytes. ')
2018-12-17T22:53:57.935025351Z 76 PC: 12a86 | Terminate with return code (Return code = '36')