Sample viewer

vx.netlux.org/Virus.DOS.AH.2241

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:53.561647431Z 255 PC: 12c64 | UNKNOWN!
2018-12-17T23:06:53.563941624Z 255 PC: 12c72 | UNKNOWN!
2018-12-17T23:06:53.565417478Z 53 PC: 12c7f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:53.568089922Z 53 PC: 12c8e | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:06:53.572957693Z 53 PC: 12c9d | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:06:53.577181734Z 82 PC: 12cab | Get DOS internal pointers (SYSVARS)
2018-12-17T23:06:53.57865297Z 74 PC: 12cbd | Reallocate memory
2018-12-17T23:06:53.580866902Z 74 PC: 12cc5 | Reallocate memory
2018-12-17T23:06:53.583501324Z 72 PC: 12d71 | Allocate memory
2018-12-17T23:06:53.5853927Z 37 PC: 12d69 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:06:53.587028065Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:06:53.59289281Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T23:06:53.596725926Z 72 PC: 9f3d1 | Allocate memory
2018-12-17T23:06:53.598905955Z 73 PC: 132d5 | Release memory