Sample viewer

vx.netlux.org/Virus.DOS.Pdp.1648

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:12.483907388Z 72 PC: 12fd9 | Allocate memory
2018-12-17T23:08:12.485944803Z 74 PC: 12ed4 | Reallocate memory
2018-12-17T23:08:12.487281366Z 72 PC: 12fd9 | Allocate memory
2018-12-17T23:08:12.490054288Z 67 PC: 17d6d | Get or set file attributes
2018-12-17T23:08:12.496110754Z 61 PC: 17d82 | Open file (Filename = '')
2018-12-17T23:08:12.502045567Z 87 PC: 17d8b | Get or set file date and time
2018-12-17T23:08:12.503423251Z 62 PC: 17d9b | Close file
2018-12-17T23:08:12.505530712Z 67 PC: 17da7 | Get or set file attributes
2018-12-17T23:08:12.821493904Z 61 PC: 17daf | Open file (Filename = '')
2018-12-17T23:08:12.827809472Z 63 PC: 17b44 | Read file or device (Read 1649 bytes on handle 5)
2018-12-17T23:08:12.834544343Z 66 PC: 17bd6 | Move file pointer
2018-12-17T23:08:12.841940019Z 64 PC: 17b8d | Write file or device (Write 1649 bytes on handle 5)
2018-12-17T23:08:12.852840958Z 66 PC: 17bd6 | Move file pointer
2018-12-17T23:08:12.854498217Z 64 PC: 17bcc | Write file or device (Write 1648 bytes on handle 5)
2018-12-17T23:08:12.862134709Z 66 PC: 17b9d | Move file pointer
2018-12-17T23:08:12.863659488Z 87 PC: 17bac | Get or set file date and time
2018-12-17T23:08:12.865157816Z 62 PC: 17bb0 | Close file
2018-12-17T23:08:12.87790303Z 67 PC: 17bbf | Get or set file attributes
2018-12-17T23:08:12.887665332Z 61 PC: 12f80 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:08:12.894634403Z 62 PC: 12f88 | Close file
2018-12-17T23:08:12.900413584Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T23:08:12.907496693Z 48 PC: 12a8f | Get DOS version
2018-12-17T23:08:12.910862844Z 67 PC: 17e17 | Get or set file attributes
2018-12-17T23:08:12.931415057Z 65 PC: 17e1e | Delete file (Filename = 'A:\TEST.COM')
2018-12-17T23:08:12.943059891Z 67 PC: 17d6d | Get or set file attributes
2018-12-17T23:08:12.949456787Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T23:08:12.958470226Z 76 PC: 12ae3 | Terminate with return code (Return code = '0')