Sample viewer

vx.netlux.org/Virus.DOS.Luce.3600

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:13.919501811Z 84 PC: 12c44 | Get verify flag
2018-12-17T23:00:13.920822797Z 42 PC: 12c50 | Get date 0x12c50: mov byte ptr cs:[0x232], al
0x12c54: mov word ptr cs:[0x22e], dx
0x12c59: mov word ptr cs:[0x230], cx
0x12c5e: xor bx, bx
0x12c60: mov cx, 0xf5
0x12c63: sub word ptr [bx + 2], cx
0x12c66: mov ax, ds
0x12c68: dec ax
0x12c69: mov ds, ax
0x12c6b: inc ax
0x12c6c: add ax, word ptr [bx + 3]
0x12c6f: sub ax, cx
0x12c71: mov es, ax
0x12c73: sub ax, 0xe
0x12c76: push ax
0x12c77: mov word ptr es:[bx + 1], 8
0x12c7d: mov word ptr es:[bx + 0x10], 0x40
0x12c83: mov al, byte ptr [bx]
0x12c85: mov byte ptr es:[bx], al
0x12c88: mov byte ptr [bx], 0x4d
2018-12-17T23:00:13.924219039Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00000064h/0000000100d bytes. ')
2018-12-17T23:00:13.928933755Z 76 PC: 12a86 | Terminate with return code (Return code = '36')