Sample viewer

vx.netlux.org/Virus.DOS.CmosDead.4792

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:59.916408484Z 77 PC: 1490a | Get program return code
2018-12-17T22:38:59.918854467Z 82 PC: 14915 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:38:59.92167016Z 220 PC: 9f5a1 | UNKNOWN!
2018-12-17T22:38:59.923029008Z 42 PC: 9f7fc | Get date 0x9f7fc: cmp bp, 0xe57
0x9f800: je 0x9f805
0x9f802: jmp 0x9f625
0x9f805: push cs
0x9f806: pop es
0x9f807: mov si, 0x39c
0x9f80a: mov cx, 0x1c8
0x9f80d: call 0xaead6
0x9f810: mov si, 0x10dc
0x9f813: mov cx, 0x49
0x9f816: call 0xaead6
0x9f819: mov si, 3
0x9f81c: inc sp
0x9f81d: or ax, 0x46ef
2018-12-17T22:38:59.92617267Z 53 PC: 9ecab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:59.9297178Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000011A0h/0000004512d bytes. ')
2018-12-17T22:38:59.934226081Z 76 PC: 12a86 | Terminate with return code (Return code = '36')