Sample viewer

vx.netlux.org/Virus.DOS.Explorer.3037

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:42.013671499Z 53 PC: 13bd7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:42.030970583Z 82 PC: 13c2f | Get DOS internal pointers (SYSVARS)
2018-12-17T23:11:42.033140624Z 53 PC: 9f27c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:42.034912135Z 37 PC: 9f28e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:42.03680766Z 37 PC: 9f8bd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:42.039846706Z 65 PC: 9f8c4 | Delete file (Filename = '')
2018-12-17T23:11:42.046888869Z 65 PC: 9f8cb | Delete file (Filename = 'AME ')
2018-12-17T23:11:42.053699427Z 98 PC: 9f8d1 | Get current PSP
2018-12-17T23:11:42.056874799Z 47 PC: 9f94f | Get disk transfer address
2018-12-17T23:11:42.058894257Z 26 PC: 9f95b | Set disk transfer address
2018-12-17T23:11:42.060836981Z 78 PC: 9f7a4 | Find first file
2018-12-17T23:11:42.072807293Z 26 PC: 9f986 | Set disk transfer address
2018-12-17T23:11:42.080852373Z 51 PC: 9f29e | Get or set Ctrl-Break
2018-12-17T23:11:42.08245104Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000011A0h/0000004512d bytes. ')
2018-12-17T23:11:42.087984356Z 76 PC: 12a86 | Terminate with return code (Return code = '36')