Sample viewer

vx.netlux.org/Virus.DOS.Nephew.2906

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:03.409963851Z 53 PC: 12e1d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:03.413014397Z 53 PC: 12e2c | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T23:05:03.414751755Z 53 PC: 12e3b | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:05:03.418238953Z 53 PC: 12e45 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:03.420836637Z 37 PC: 12e59 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:03.422435043Z 48 PC: 12e6f | Get DOS version
2018-12-17T23:05:03.423982033Z 37 PC: 12e85 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:03.425275856Z 82 PC: 1365d | Get DOS internal pointers (SYSVARS)
2018-12-17T23:05:03.427353273Z 50 PC: 13696 | Get disk parameter block for specified drive
2018-12-17T23:05:03.434123304Z 37 PC: 12eee | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:03.436760483Z 37 PC: 12ef6 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T23:05:03.441686688Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:05:03.446538872Z 76 PC: 12a86 | Terminate with return code (Return code = '36')