Sample viewer

vx.netlux.org/Virus.DOS.Lichen.1024.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:03:43.130289837Z 62 PC: 12b9a | Close file
2018-12-17T22:03:43.13338045Z 73 PC: 12bbb | Release memory
2018-12-17T22:03:43.135189254Z 72 PC: 12bc2 | Allocate memory
2018-12-17T22:03:43.137453914Z 72 PC: 12bc9 | Allocate memory
2018-12-17T22:03:43.140288238Z 72 PC: 12bcf | Allocate memory
2018-12-17T22:03:43.142491034Z 42 PC: 12be1 | Get date 0x12be1: mov ax, cx
0x12be3: mov bx, dx
0x12be5: xchg word ptr es:[0xed], cx
0x12bea: xchg word ptr es:[0xef], dx
0x12bef: dec bh
0x12bf1: jne 0x12bf6
0x12bf3: mov bh, 0xc
0x12bf5: dec ax
0x12bf6: cmp ax, cx
0x12bf8: jne 0x12bfc
0x12bfa: cmp bx, dx
0x12bfc: pushf
0x12bfd: mov cx, es
0x12bff: shl ecx, 0x10
0x12c03: mov cx, 0x244
0x12c06: mov bx, 0x20
0x12c09: mov di, 0x246
0x12c0c: popf
0x12c0d: jb 0x12c1d
0x12c0f: call 0x12c7e
2018-12-17T22:03:43.145334889Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:03:43.151025708Z 76 PC: 12a86 | Terminate with return code (Return code = '36')