Sample viewer

vx.netlux.org/Virus.DOS.VGOL.1837

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:30.465574655Z 67 PC: 15ddf | Get or set file attributes
2018-12-17T22:24:30.471945602Z 61 PC: 15ddf | Open file (Filename = 'p')
2018-12-17T22:24:30.477894735Z 87 PC: 15ddf | Get or set file date and time
2018-12-17T22:24:30.479227832Z 63 PC: 15ddf | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:24:30.482850821Z 66 PC: 15ddf | Move file pointer
2018-12-17T22:24:30.484160628Z 66 PC: 15e71 | Move file pointer
2018-12-17T22:24:30.485402888Z 63 PC: 15e7b | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:24:30.48823598Z 66 PC: 15ddf | Move file pointer
2018-12-17T22:24:30.489981586Z 64 PC: 15ddf | Write file or device (Write 1837 bytes on handle 5)
2018-12-17T22:24:30.843076804Z 64 PC: 15f7b | Write file or device (Write 7 bytes on handle 5)
2018-12-17T22:24:30.845961102Z 66 PC: 15ddf | Move file pointer
2018-12-17T22:24:30.848023959Z 64 PC: 15ddf | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:24:30.850054029Z 87 PC: 15ddf | Get or set file date and time
2018-12-17T22:24:30.852994454Z 62 PC: 15ddf | Close file
2018-12-17T22:24:30.860499028Z 65 PC: 15ddf | Delete file (Filename = '')
2018-12-17T22:24:30.865563587Z 75 PC: 15fe5 | Execute program
2018-12-17T22:24:30.869345601Z 74 PC: 16005 | Reallocate memory
2018-12-17T22:24:30.871695789Z 82 PC: 1600a | Get DOS internal pointers (SYSVARS)
2018-12-17T22:24:30.873475704Z 53 PC: 16064 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:30.875920379Z 37 PC: 1607a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:30.877957307Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00003300h/0000013056d bytes. ')
2018-12-17T22:24:30.882715342Z 76 PC: 12a86 | Terminate with return code (Return code = '36')