Sample viewer

vx.netlux.org/Virus.DOS.Tamagoci.2700

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:52.249743359Z 2 PC: 1515a | Character output (Char = '08')
2018-12-17T22:59:52.253617152Z 254 PC: 151c3 | UNKNOWN!
2018-12-17T22:59:52.254911802Z 73 PC: 151ce | Release memory
2018-12-17T22:59:52.2567632Z 72 PC: 151d7 | Allocate memory
2018-12-17T22:59:52.259430898Z 74 PC: 151e5 | Reallocate memory
2018-12-17T22:59:52.263929418Z 74 PC: 151f5 | Reallocate memory
2018-12-17T22:59:52.266972972Z 53 PC: 15201 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:59:52.269504755Z 53 PC: 15218 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:52.27190328Z 82 PC: 15225 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:59:52.275810861Z 48 PC: 15266 | Get DOS version
2018-12-17T22:59:52.278437822Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00002710h/0000010000d bytes. ')
2018-12-17T22:59:52.285380062Z 42 PC: 9ec09 | Get date 0x9ec09: ret
0x9ec0a: add word ptr [si + 0x5350], bx
0x9ec0e: push cx
0x9ec0f: push dx
0x9ec10: push es
0x9ec11: push ds
0x9ec12: push si
0x9ec13: push di
0x9ec14: push bp
0x9ec15: cld
0x9ec16: push cs
0x9ec17: push cs
0x9ec18: pop ds
0x9ec19: pop es
0x9ec1a: cmp byte ptr cs:[0x55a], 1
0x9ec20: je 0x9ec39
0x9ec22: call 0x9edff
0x9ec25: mov byte ptr cs:[0x55a], 1
0x9ec2b: jae 0x9ec2f
0x9ec2d: jmp 0x9ec64
2018-12-17T22:59:52.287835586Z 44 PC: 9ec09 | Get time 0x9ec09: ret
0x9ec0a: add word ptr [si + 0x5350], bx
0x9ec0e: push cx
0x9ec0f: push dx
0x9ec10: push es
0x9ec11: push ds
0x9ec12: push si
0x9ec13: push di
0x9ec14: push bp
0x9ec15: cld
0x9ec16: push cs
0x9ec17: push cs
0x9ec18: pop ds
0x9ec19: pop es
0x9ec1a: cmp byte ptr cs:[0x55a], 1
0x9ec20: je 0x9ec39
0x9ec22: call 0x9edff
0x9ec25: mov byte ptr cs:[0x55a], 1
0x9ec2b: jae 0x9ec2f
0x9ec2d: jmp 0x9ec64
2018-12-17T22:59:52.631728398Z 76 PC: 12a86 | Terminate with return code (Return code = '36')