Sample viewer

vx.netlux.org/Virus.DOS.Yosha.938

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:25.594243471Z 47 PC: 137fa | Get disk transfer address
2018-12-17T22:02:25.596580385Z 30 PC: 13895 | Reserved
2018-12-17T22:02:25.598531803Z 30 PC: 13895 | Reserved
2018-12-17T22:02:25.600223719Z 9 PC: 12ab8 | Display string (String= 'Goat file (COM/mpi.). Size=00000DACh/0000003500d bytes. ')
2018-12-17T22:02:25.606595473Z 48 PC: 12ac1 | Get DOS version
2018-12-17T22:02:25.608176545Z 42 PC: 9f743 | Get date 0x9f743: cmp dx, 0x4c9
0x9f747: je 0x9f76c
0x9f749: mov ah, 0x62
0x9f74b: int 0x60
0x9f74d: dec bx
0x9f74e: mov es, bx
0x9f750: cld
0x9f751: mov si, 8
0x9f754: lodsw ax, word ptr es:[si]
0x9f756: mov bl, 0
0x9f758: cmp ax, 0x4843
0x9f75b: jne 0x9f75e
0x9f75d: inc bx
0x9f75e: cmp ax, 0x4b50
0x9f761: jne 0x9f764
0x9f763: inc bx
0x9f764: mov byte ptr [0x3b8], bl
0x9f768: pop ds
0x9f769: pop es
0x9f76a: popaw
2018-12-17T22:02:25.610848736Z 98 PC: 9f74d | Get current PSP
2018-12-17T22:02:25.612356126Z 61 PC: 9f71a | Open file (Filename = '')
2018-12-17T22:02:25.620261762Z 87 PC: 9f6ee | Get or set file date and time
2018-12-17T22:02:25.622008858Z 63 PC: 9f714 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:02:25.624356494Z 66 PC: 9f636 | Move file pointer
2018-12-17T22:02:25.626227328Z 63 PC: 9f714 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:02:25.634798424Z 66 PC: 9f714 | Move file pointer
2018-12-17T22:02:25.636510341Z 64 PC: 9f647 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:02:25.65795734Z 66 PC: 9f714 | Move file pointer
2018-12-17T22:02:25.659573956Z 64 PC: 9f714 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:02:25.662568241Z 87 PC: 9f6c3 | Get or set file date and time
2018-12-17T22:02:25.666102913Z 62 PC: 9f6ce | Close file
2018-12-17T22:02:25.672176919Z 61 PC: 12b8e | Open file (Filename = '')
2018-12-17T22:02:25.678839601Z 93 PC: 12b30 | File sharing functions
2018-12-17T22:02:25.682047555Z 76 PC: 12b15 | Terminate with return code (Return code = '0')