Sample viewer

vx.netlux.org/Virus.DOS.Fumble.867.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:24.490071865Z 26 PC: 12bcd | Set disk transfer address
2018-12-17T22:20:24.498298607Z 42 PC: 12bdd | Get date 0x12bdd: test dl, 1
0x12be0: jne 0x12c01
0x12be2: mov dx, si
0x12be4: add dx, 5
0x12be8: xor cx, cx
0x12bea: mov ah, 0x4e
0x12bec: int 0x21
0x12bee: jb 0x12c01
0x12bf0: call 0x12c1f
0x12bf3: mov dx, si
0x12bf5: add dx, 5
0x12bf9: xor cx, cx
0x12bfb: mov ah, 0x4f
0x12bfd: int 0x21
0x12bff: jae 0x12bf0
0x12c01: mov al, byte ptr [si + 0x12]
0x12c04: mov byte ptr [0x100], al
0x12c07: mov ax, word ptr [si + 0x13]
0x12c0a: mov word ptr [0x101], ax
0x12c0d: mov dx, 0x80
2018-12-17T22:20:24.500908925Z 26 PC: 12c14 | Set disk transfer address
2018-12-17T22:20:24.502369958Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:20:24.508661479Z 74 PC: 12de4 | Reallocate memory
2018-12-17T22:20:24.510362682Z 49 PC: 12a86 | Terminate and stay resident (Return code = '126' | Memory size = '30')