Sample viewer

vx.netlux.org/Virus.DOS.XPEH.4048

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:38.220716453Z 42 PC: 13187 | Get date 0x13187: cmp cx, word ptr [bp + 4]
0x1318a: jb 0x13194
0x1318c: cmp dh, byte ptr [bp + 6]
0x1318f: jb 0x13194
0x13191: clc
0x13192: jmp 0x13195
0x13194: stc
0x13195: pop dx
0x13196: pop cx
0x13197: pop ax
0x13198: pop bp
0x13199: ret 4
0x1319c: push bp
0x1319d: mov bp, sp
0x1319f: push cx
0x131a0: push di
0x131a1: push es
0x131a2: push bx
0x131a3: push ax
0x131a4: cld
2018-12-17T22:28:38.232233703Z 37 PC: 13625 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:28:38.233739816Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:28:38.237918816Z 76 PC: 12a86 | Terminate with return code (Return code = '36')