Sample viewer

vx.netlux.org/Virus.DOS.Nephew.3760

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:25.530070841Z 53 PC: 135b8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:25.540235748Z 53 PC: 135c7 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:19:25.541557848Z 53 PC: 135d6 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:19:25.543169521Z 88 PC: 13754 | case 0xGet or set allocation strateg:
2018-12-17T22:19:25.54515852Z 88 PC: 1375a | case 0xGet or set allocation strateg:
2018-12-17T22:19:25.546842567Z 88 PC: 13765 | case 0xGet or set allocation strateg:
2018-12-17T22:19:25.548366192Z 88 PC: 1376d | case 0xGet or set allocation strateg:
2018-12-17T22:19:25.549696989Z 72 PC: 13774 | Allocate memory
2018-12-17T22:19:25.552038131Z 74 PC: 13791 | Reallocate memory
2018-12-17T22:19:25.5539219Z 82 PC: 13795 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:19:25.555483556Z 80 PC: 137b2 | Set current PSP
2018-12-17T22:19:25.556937458Z 72 PC: 137b9 | Allocate memory
2018-12-17T22:19:25.558975181Z 80 PC: 137c6 | Set current PSP
2018-12-17T22:19:25.560184548Z 88 PC: 137cc | case 0xGet or set allocation strateg:
2018-12-17T22:19:25.56261002Z 88 PC: 137d2 | case 0xGet or set allocation strateg:
2018-12-17T22:19:25.564642861Z 82 PC: 13989 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:19:25.566583138Z 50 PC: 139ce | Get disk parameter block for specified drive
2018-12-17T22:19:25.575023095Z 37 PC: 1381d | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:19:25.57770315Z 37 PC: 13825 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:25.579597302Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:19:25.585647447Z 76 PC: 12a86 | Terminate with return code (Return code = '36')