Sample viewer

vx.netlux.org/Virus.DOS.Apocalipse.1685

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:50.44037383Z 25 PC: 12da5 | Get default drive
2018-12-17T23:11:50.442419315Z 82 PC: 9f56a | Get DOS internal pointers (SYSVARS)
2018-12-17T23:11:50.44439529Z 25 PC: 9f5d5 | Get default drive
2018-12-17T23:11:50.445614206Z 53 PC: 9f9d8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:50.447975657Z 37 PC: 9f9d8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:50.790327788Z 53 PC: 9f9d8 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:11:50.791913623Z 37 PC: 9f9d8 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:11:50.793522971Z 53 PC: 9f9d8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:50.796908947Z 37 PC: 9f9d8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:50.799086403Z 54 PC: 9f9d8 | Get free disk space
2018-12-17T23:11:50.838145781Z 67 PC: 9f9d8 | Get or set file attributes
2018-12-17T23:11:50.848824144Z 37 PC: 9f9d8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:50.850153016Z 37 PC: 9f9d8 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:11:50.851684065Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:11:50.856807331Z 76 PC: 12a86 | Terminate with return code (Return code = '36')