Sample viewer

vx.netlux.org/Virus.DOS.Sunset.1079

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:52.54633564Z 154 PC: 12c30 | UNKNOWN!
2018-12-17T22:59:52.548444763Z 42 PC: 12ca5 | Get date 0x12ca5: cmp word ptr cs:[bp + 0xf0], dx
0x12caa: jne 0x12caf
0x12cac: call 0x12f5a
0x12caf: pop es
0x12cb0: pop ds
0x12cb1: jmp 0x12cc3
0x12cb4: mov ax, 0x6eb
0x12cb7: mov word ptr [0x100], ax
0x12cba: mov al, 0x90
0x12cbc: mov byte ptr [0x102], al
0x12cbf: push 0x100
0x12cc2: ret
0x12cc3: mov ax, es
0x12cc5: add ax, 0x10
0x12cc8: add word ptr cs:[bp + 0xf4], ax
0x12ccd: add word ptr cs:[bp + 0xf8], ax
0x12cd2: mov ss, word ptr cs:[bp + 0xf8]
0x12cd7: mov sp, word ptr cs:[bp + 0xf6]
0x12cdc: push 0
0x12cde: ljmp ptr cs:[bp + 0xf2]
2018-12-17T22:59:52.550556267Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T22:59:52.553073854Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T22:59:52.555247402Z 72 PC: 9fb77 | Allocate memory
2018-12-17T22:59:52.556556886Z 82 PC: 9fb7e | Get DOS internal pointers (SYSVARS)