Sample viewer

vx.netlux.org/Virus.DOS.Atomant.564

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:47.240702122Z 53 PC: 12bb0 | Get interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-17T23:01:47.243418511Z 44 PC: 12be7 | Get time 0x12be7: mov word ptr es:[0x1f6], cx
0x12bec: push es
0x12bed: pop ds
0x12bee: xor ax, ax
0x12bf0: mov es, ax
0x12bf2: mov ax, word ptr es:[0x84]
0x12bf6: mov bx, word ptr es:[0x86]
0x12bfb: mov word ptr [0x1ec], ax
0x12bfe: mov word ptr [0x1ee], bx
0x12c02: mov ax, word ptr es:[0x200]
0x12c06: mov bx, word ptr es:[0x202]
0x12c0b: mov word ptr [0x1e8], ax
0x12c0e: mov word ptr [0x1ea], bx
0x12c12: cli
0x12c13: mov ax, 0xb2
0x12c16: mov bx, ds
0x12c18: mov word ptr es:[0x84], ax
0x12c1c: mov word ptr es:[0x86], bx
0x12c21: mov ax, 0x1af
0x12c24: mov word ptr es:[0x200], ax
2018-12-17T23:01:47.247080503Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:01:47.25287338Z 76 PC: 12a86 | Terminate with return code (Return code = '36')