Sample viewer

vx.netlux.org/Virus.DOS.Warrior_II.806

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:09.671106007Z 47 PC: 13357 | Get disk transfer address
2018-12-17T23:05:09.67463009Z 26 PC: 13361 | Set disk transfer address
2018-12-17T23:05:09.676116764Z 78 PC: 1336a | Find first file
2018-12-17T23:05:09.683444501Z 47 PC: 13373 | Get disk transfer address
2018-12-17T23:05:09.684515039Z 67 PC: 13391 | Get or set file attributes
2018-12-17T23:05:09.691832913Z 61 PC: 133aa | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:05:09.69949619Z 66 PC: 133bc | Move file pointer
2018-12-17T23:05:09.701542166Z 87 PC: 133d3 | Get or set file date and time
2018-12-17T23:05:09.703974775Z 66 PC: 1347c | Move file pointer
2018-12-17T23:05:09.705832042Z 63 PC: 1348b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:09.712953748Z 66 PC: 134b0 | Move file pointer
2018-12-17T23:05:09.715442964Z 64 PC: 134bf | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:05:09.71842345Z 66 PC: 134d8 | Move file pointer
2018-12-17T23:05:09.719979467Z 64 PC: 134f5 | Write file or device (Write 806 bytes on handle 5)
2018-12-17T23:05:09.736406538Z 87 PC: 1350c | Get or set file date and time
2018-12-17T23:05:09.738046382Z 62 PC: 13514 | Close file
2018-12-17T23:05:09.746948753Z 67 PC: 1357d | Get or set file attributes
2018-12-17T23:05:09.759317757Z 26 PC: 1351d | Set disk transfer address
2018-12-17T23:05:09.77980497Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T23:05:09.783383672Z 48 PC: 12a8f | Get DOS version
2018-12-17T23:05:09.784864644Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T23:05:09.790692813Z 93 PC: 12afe | File sharing functions
2018-12-17T23:05:09.79226598Z 9 PC: 12a86 | Display string (String= 'Size change=0326h/00806d. ')
2018-12-17T23:05:09.796509371Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')