Sample viewer

vx.netlux.org/Virus.DOS.Sirius.614

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:14.612741429Z 53 PC: 13e78 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:14.614195973Z 37 PC: 13e8c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:14.616245511Z 47 PC: 13e91 | Get disk transfer address
2018-12-17T23:06:14.617504559Z 26 PC: 13ea3 | Set disk transfer address
2018-12-17T23:06:14.61873678Z 25 PC: 13ea7 | Get default drive
2018-12-17T23:06:14.620896942Z 71 PC: 13eb4 | Get current directory
2018-12-17T23:06:14.624559987Z 14 PC: 1406a | Set default drive (Drive = 'A')
2018-12-17T23:06:14.626423817Z 59 PC: 14060 | Change current directory
2018-12-17T23:06:14.63752861Z 59 PC: 14072 | Change current directory
2018-12-17T23:06:14.639680271Z 37 PC: 1403d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:14.641093759Z 26 PC: 1404d | Set disk transfer address
2018-12-17T23:06:14.643530939Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T23:06:14.650259283Z 0 PC: 12a89 | Program terminate