Sample viewer

vx.netlux.org/Virus.DOS.F3.1901

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:55.256653208Z 51 PC: 14453 | Get or set Ctrl-Break
2018-12-17T23:02:55.258447188Z 42 PC: 9fad5 | Get date 0x9fad5: push dx
0x9fad6: push cx
0x9fad7: cmp word ptr cs:[0x126], cx
0x9fadc: jne 0x9faf4
0x9fade: cmp byte ptr cs:[0x125], dh
0x9fae3: jne 0x9faf4
0x9fae5: sub dl, 3
0x9fae8: cmp byte ptr cs:[0x124], dl
0x9faed: jb 0x9faf4
0x9faef: pop ax
0x9faf0: pop ax
0x9faf1: jmp 0x9fb9a
0x9faf4: mov ax, 0x21
0x9faf7: mov cx, 4
0x9fafa: xor dx, dx
0x9fafc: mul cx
0x9fafe: mov si, ax
0x9fb00: mov ds, dx
0x9fb02: mov ax, word ptr [si]
0x9fb04: mov dx, word ptr [si + 2]
2018-12-17T23:02:55.2616525Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T23:02:55.265732665Z 0 PC: 12a89 | Program terminate