Sample viewer

vx.netlux.org/Virus.DOS.Maverick.3584

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:46.137838409Z 98 PC: 13a41 | Get current PSP
2018-12-17T22:49:46.140215306Z 42 PC: 13b26 | Get date 0x13b26: pop si
0x13b27: mov byte ptr cs:[si + 0xab5], al
0x13b2c: push es
0x13b2d: call 0x141e3
0x13b30: add si, 0xb33
0x13b34: pop dx
0x13b35: xor ax, ax
0x13b37: mov bx, ax
0x13b39: mov es, dx
0x13b3b: mov ds, dx
0x13b3d: mov cx, ss
0x13b3f: cmp cx, dx
0x13b41: jne 0x13b4d
0x13b43: mov di, 0x100
0x13b46: push di
0x13b47: mov cx, 0xc
0x13b4a: rep movsd dword ptr es:[di], dword ptr [si]
0x13b4c: ret
0x13b4d: add dx, 0x10
0x13b50: mov cx, dx
2018-12-17T22:49:46.197482858Z 108 PC: 141fc | Extended open/create file
2018-12-17T22:49:46.199613467Z 78 PC: 14223 | Find first file
2018-12-17T22:49:46.206041731Z 47 PC: 14229 | Get disk transfer address
2018-12-17T22:49:46.207219443Z 79 PC: 14258 | Find next file
2018-12-17T22:49:46.209896002Z 47 PC: 14229 | Get disk transfer address
2018-12-17T22:49:46.211106862Z 79 PC: 14258 | Find next file
2018-12-17T22:49:46.215825155Z 47 PC: 14229 | Get disk transfer address
2018-12-17T22:49:46.217369292Z 79 PC: 14258 | Find next file
2018-12-17T22:49:46.220214012Z 47 PC: 14229 | Get disk transfer address
2018-12-17T22:49:46.222665098Z 79 PC: 14258 | Find next file
2018-12-17T22:49:46.225358652Z 47 PC: 14229 | Get disk transfer address
2018-12-17T22:49:46.226573505Z 79 PC: 14258 | Find next file
2018-12-17T22:49:46.22955371Z 78 PC: 14223 | Find first file
2018-12-17T22:49:46.231692741Z 88 PC: 13b75 | case 0xGet or set allocation strateg:
2018-12-17T22:49:46.23290686Z 82 PC: 13b7b | Get DOS internal pointers (SYSVARS)
2018-12-17T22:49:46.234666684Z 82 PC: 13bff | Get DOS internal pointers (SYSVARS)
2018-12-17T22:49:46.23582667Z 53 PC: 13c32 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:49:46.236949587Z 37 PC: 13c45 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:49:46.238923938Z 51 PC: 13c53 | Get or set Ctrl-Break
2018-12-17T22:49:46.239847951Z 37 PC: 13c5e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:49:46.240586128Z 37 PC: 13c6a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:46.241611692Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000011A0h/0000004512d bytes. ')
2018-12-17T22:49:46.244563518Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T22:49:46.247596269Z 72 PC: 9f165 | Allocate memory
2018-12-17T22:49:46.249485947Z 37 PC: 9f15b | Set interrupt vector (Interrupt = '33' AKA 'Random read')