Sample viewer

vx.netlux.org/Virus.DOS.Nephew.3758

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:34.043686957Z 53 PC: 135b4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:34.045610057Z 53 PC: 135c3 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:58:34.046760705Z 53 PC: 135d2 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:58:34.048078299Z 88 PC: 13752 | case 0xGet or set allocation strateg:
2018-12-17T22:58:34.04914174Z 88 PC: 13758 | case 0xGet or set allocation strateg:
2018-12-17T22:58:34.050537921Z 88 PC: 13763 | case 0xGet or set allocation strateg:
2018-12-17T22:58:34.051794677Z 88 PC: 1376b | case 0xGet or set allocation strateg:
2018-12-17T22:58:34.052975312Z 72 PC: 13772 | Allocate memory
2018-12-17T22:58:34.055120649Z 74 PC: 1378f | Reallocate memory
2018-12-17T22:58:34.056327565Z 82 PC: 13793 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:58:34.057353324Z 80 PC: 137b0 | Set current PSP
2018-12-17T22:58:34.058526111Z 72 PC: 137b7 | Allocate memory
2018-12-17T22:58:34.0598493Z 80 PC: 137c4 | Set current PSP
2018-12-17T22:58:34.060639772Z 88 PC: 137ca | case 0xGet or set allocation strateg:
2018-12-17T22:58:34.062462916Z 88 PC: 137d0 | case 0xGet or set allocation strateg:
2018-12-17T22:58:34.064016062Z 82 PC: 13987 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:58:34.065768702Z 50 PC: 139cc | Get disk parameter block for specified drive
2018-12-17T22:58:34.073820449Z 37 PC: 1381b | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:58:34.075691714Z 37 PC: 13823 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:34.077226472Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:58:34.083483233Z 76 PC: 12a86 | Terminate with return code (Return code = '36')