Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.508

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:32.008026398Z 65 PC: 139ff | Delete file (Filename = '¸C†àÍ!Ãed by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-17T23:07:32.013458731Z 74 PC: 13a0b | Reallocate memory
2018-12-17T23:07:32.015233897Z 74 PC: 13a12 | Reallocate memory
2018-12-17T23:07:32.016740369Z 72 PC: 13a20 | Allocate memory
2018-12-17T23:07:32.018655229Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000FA0h/0000004000d bytes. ')
2018-12-17T23:07:32.025523068Z 48 PC: 12a8f | Get DOS version
2018-12-17T23:07:32.027109501Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T23:07:32.034587678Z 93 PC: 12afe | File sharing functions
2018-12-17T23:07:32.038300648Z 9 PC: 12a86 | Display string (String= 'Size change=01FCh/00508d. ')
2018-12-17T23:07:32.042670812Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')