Sample viewer

vx.netlux.org/Virus.DOS.Rajaat.147

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:30.525986761Z 26 PC: 12a4a | Set disk transfer address
2018-12-17T23:11:30.528158061Z 78 PC: 12a52 | Find first file
2018-12-17T23:11:30.534431526Z 61 PC: 12a64 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:11:30.54119046Z 63 PC: 12a73 | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:11:30.548243165Z 62 PC: 12a7a | Close file
2018-12-17T23:11:30.550834152Z 60 PC: 12a81 | Create or truncate file
2018-12-17T23:11:30.817188057Z 64 PC: 12a8b | Write file or device (Write 147 bytes on handle 5)
2018-12-17T23:11:30.821468166Z 64 PC: 12a92 | Write file or device (Write 407 bytes on handle 5)
2018-12-17T23:11:30.830098764Z 87 PC: 12aa4 | Get or set file date and time
2018-12-17T23:11:30.831323328Z 62 PC: 12aa8 | Close file
2018-12-17T23:11:30.838933709Z 26 PC: 12ad2 | Set disk transfer address
2018-12-17T23:11:30.840694493Z 9 PC: 12b18 | Display string (String= '�<�Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T23:11:30.845912482Z 0 PC: 12b1c | Program terminate