Sample viewer

vx.netlux.org/Virus.DOS.Cordobes.3294

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:14.297124753Z 240 PC: 17c60 | UNKNOWN!
2018-12-17T22:45:14.29935879Z 74 PC: 12ada | Reallocate memory
2018-12-17T22:45:14.300512138Z 42 PC: 13699 | Get date 0x13699: mov ax, word ptr cs:[0x14a]
0x1369d: add ah, 4
0x136a0: cmp ah, 0xc
0x136a3: jbe 0x136a8
0x136a5: sub ah, 0xc
0x136a8: mov word ptr cs:[0x14a], dx
0x136ad: cmp dx, ax
0x136af: jne 0x136d6
0x136b1: push cs
0x136b2: pop ds
0x136b3: mov dx, 0x157
0x136b6: mov ax, 0x3d92
0x136b9: int 0x21
0x136bb: jb 0x136d6
0x136bd: mov bx, ax
0x136bf: mov ax, 0x4202
0x136c2: xor dx, dx
0x136c4: xor cx, cx
0x136c6: int 0x21
0x136c8: mov ah, 0x40
2018-12-17T22:45:14.302428722Z 53 PC: 12ae2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:14.303863713Z 37 PC: 12af6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:14.30491595Z 75 PC: 12b34 | Execute program
2018-12-17T22:45:14.320003923Z 9 PC: 13ac2 | Display string (String= 'Goat file (EXE). Size=000053DDh/0000021469d bytes. ')
2018-12-17T22:45:14.32466528Z 76 PC: 13ac6 | Terminate with return code (Return code = '36')
2018-12-17T22:45:14.327364689Z 77 PC: 12b4d | Get program return code
2018-12-17T22:45:14.328890552Z 49 PC: 12b60 | Terminate and stay resident (Return code = '36' | Memory size = '254')