Sample viewer

vx.netlux.org/Virus.DOS.Freedom.2448

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:38.480496294Z 48 PC: 13a82 | Get DOS version
2018-12-17T22:43:38.483090819Z 74 PC: 12b09 | Reallocate memory
2018-12-17T22:43:38.485028143Z 44 PC: 12b0d | Get time 0x12b0d: mov word ptr cs:[0x651], dx
0x12b12: add dl, dh
0x12b14: mov byte ptr cs:[0x96f], dl
0x12b19: mov byte ptr cs:[0x20c], 0
0x12b1f: mov byte ptr cs:[0x5db], 0xa
0x12b25: nop
0x12b26: mov byte ptr cs:[0x210], 0
0x12b2c: nop
0x12b2d: mov byte ptr cs:[0x48a], 0
0x12b33: mov ah, 8
0x12b35: mov dl, 0x80
0x12b37: int 0x13
0x12b39: jb 0x12b40
0x12b3b: mov byte ptr cs:[0x48a], dl
0x12b40: sub ax, ax
0x12b42: mov ds, ax
0x12b44: mov word ptr [0x200], 0xaaaa
0x12b4a: mov ax, word ptr [0x84]
0x12b4d: mov word ptr cs:[0x26], ax
0x12b51: mov word ptr cs:[0x22], ax
2018-12-17T22:43:38.488980625Z 51 PC: 12b97 | Get or set Ctrl-Break
2018-12-17T22:43:38.492367305Z 75 PC: 12be1 | Execute program
2018-12-17T22:43:38.510628619Z 9 PC: 13572 | Display string (String= 'Goat file (EXE). Size=000011A0h/0000004512d bytes. ')
2018-12-17T22:43:38.515249833Z 76 PC: 13576 | Terminate with return code (Return code = '36')
2018-12-17T22:43:38.518739124Z 49 PC: 12be9 | Terminate and stay resident (Return code = '0' | Memory size = '169')