Sample viewer

vx.netlux.org/Virus.DOS.Gro.1903

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:45.685715213Z 234 PC: 12c62 | UNKNOWN!
2018-12-17T22:29:45.687859161Z 53 PC: 12c73 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:29:45.689121178Z 53 PC: 13239 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:29:45.690425296Z 37 PC: 1324e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:29:45.693008807Z 37 PC: 1326e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:29:45.694088107Z 53 PC: 12cab | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:45.695090299Z 53 PC: 13239 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:29:45.696672588Z 37 PC: 1324e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:29:45.697695013Z 48 PC: 13260 | Get DOS version
2018-12-17T22:29:45.698839433Z 37 PC: 1326e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:29:45.700396777Z 37 PC: 12d20 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:45.701612092Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T22:29:45.704050136Z 76 PC: 12a86 | Terminate with return code (Return code = '36')