Sample viewer

vx.netlux.org/Virus.DOS.Yellow.1361

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:04:20.259125261Z 119 PC: 12a4e | UNKNOWN!
2018-12-17T22:04:20.26084663Z 119 PC: 12a99 | UNKNOWN!
2018-12-17T22:04:20.262430231Z 74 PC: 12b42 | Reallocate memory
2018-12-17T22:04:20.264021959Z 53 PC: 12b55 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:20.265923189Z 53 PC: 12b64 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:20.267114479Z 53 PC: 12b73 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:04:20.268372317Z 37 PC: 12b88 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:20.270193437Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:20.271359091Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:04:20.272546749Z 75 PC: 12bd0 | Execute program
2018-12-17T22:04:20.286745248Z 9 PC: 13333 | Display string (String= 'This is a COM sacrificial goat exactly 400H bytes long ')
2018-12-17T22:04:20.290740546Z 0 PC: 13337 | Program terminate
2018-12-17T22:04:20.293649752Z 73 PC: 12bd6 | Release memory
2018-12-17T22:04:20.296984661Z 77 PC: 12bda | Get program return code
2018-12-17T22:04:20.299158912Z 49 PC: 12be8 | Terminate and stay resident (Return code = '0' | Memory size = '102')