Sample viewer

vx.netlux.org/Virus.DOS.Lichen.1024

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:27.484077779Z 62 PC: 12b9a | Close file
2018-12-17T22:23:27.486094696Z 73 PC: 12bab | Release memory
2018-12-17T22:23:27.487265903Z 72 PC: 12bb2 | Allocate memory
2018-12-17T22:23:27.489128992Z 72 PC: 12bb9 | Allocate memory
2018-12-17T22:23:27.491627623Z 72 PC: 12bc0 | Allocate memory
2018-12-17T22:23:27.493600592Z 42 PC: 12bd2 | Get date 0x12bd2: mov ax, cx
0x12bd4: mov bx, dx
0x12bd6: xchg word ptr es:[0xde], cx
0x12bdb: xchg word ptr es:[0xe0], dx
0x12be0: dec bh
0x12be2: jne 0x12be7
0x12be4: mov bh, 0xc
0x12be6: dec ax
0x12be7: cmp ax, cx
0x12be9: jne 0x12bed
0x12beb: cmp bx, dx
0x12bed: pushf
0x12bee: mov cx, es
0x12bf0: shl ecx, 0x10
0x12bf4: mov cx, 0x22c
0x12bf7: mov bx, 0x20
0x12bfa: mov di, 0x22e
0x12bfd: popf
0x12bfe: jb 0x12c0e
0x12c00: call 0x12c6f
2018-12-17T22:23:27.496314055Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:23:27.50116568Z 76 PC: 12a86 | Terminate with return code (Return code = '36')