Sample viewer

vx.netlux.org/Virus.DOS.KGK.1020

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:01.84486484Z 119 PC: 139ee | UNKNOWN!
2018-12-17T23:03:01.851221217Z 42 PC: 9f83e | Get date 0x9f83e: mov ax, 0xf000
0x9f841: mov ds, ax
0x9f843: mov si, word ptr [0xe000]
0x9f847: cmp word ptr cs:[0x4f9], si
0x9f84c: je 0x9f858
0x9f84e: mov word ptr cs:[0x4f9], si
0x9f853: mov byte ptr cs:[0x4fb], dh
0x9f858: push cs
0x9f859: pop ds
0x9f85a: cmp byte ptr [0x4fb], dh
0x9f85e: je 0x9f886
0x9f860: mov byte ptr [0x4fb], dh
0x9f864: mov ah, 9
0x9f866: mov dx, 0x48e
0x9f869: int 0x21
0x9f86b: mov ax, 0x351c
0x9f86e: int 0x21
0x9f870: push bx
0x9f871: push es
0x9f872: mov ah, 0x25
2018-12-17T23:03:01.853916238Z 53 PC: 9f88b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:01.855226735Z 37 PC: 9f89a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:01.857658685Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000011A0h/0000004512d bytes. ')
2018-12-17T23:03:01.864657501Z 76 PC: 12a86 | Terminate with return code (Return code = '36')