Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.240

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:49.804323638Z 26 PC: 12b9c | Set disk transfer address
2018-12-17T23:12:49.806034914Z 78 PC: 12baf | Find first file
2018-12-17T23:12:49.811801658Z 61 PC: 12bb7 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:49.817959161Z 87 PC: 12bc2 | Get or set file date and time
2018-12-17T23:12:49.819500445Z 63 PC: 12bdd | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:49.826061962Z 66 PC: 12c28 | Move file pointer
2018-12-17T23:12:49.827424218Z 66 PC: 12c28 | Move file pointer
2018-12-17T23:12:49.828747692Z 64 PC: 12c41 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:12:49.831716689Z 64 PC: 12c4c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T23:12:49.835063042Z 66 PC: 12c28 | Move file pointer
2018-12-17T23:12:49.83662295Z 64 PC: 12c04 | Write file or device (Write 240 bytes on handle 5)
2018-12-17T23:12:49.849497602Z 87 PC: 12c11 | Get or set file date and time
2018-12-17T23:12:49.850823102Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:12:49.854725493Z 76 PC: 12a86 | Terminate with return code (Return code = '36')