Sample viewer

vx.netlux.org/Virus.DOS.IR.469

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:08:34.492459095Z 26 PC: 1341a | Set disk transfer address
2018-12-17T22:08:34.494321149Z 71 PC: 13424 | Get current directory
2018-12-17T22:08:34.49711625Z 78 PC: 1342e | Find first file
2018-12-17T22:08:34.502767791Z 67 PC: 1344c | Get or set file attributes
2018-12-17T22:08:34.606668354Z 61 PC: 13456 | Open file (Filename = 'è')
2018-12-17T22:08:34.613453378Z 63 PC: 13467 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:08:34.619805401Z 87 PC: 134ee | Get or set file date and time
2018-12-17T22:08:34.621255739Z 62 PC: 134f2 | Close file
2018-12-17T22:08:34.625906442Z 67 PC: 13503 | Get or set file attributes
2018-12-17T22:08:34.63224978Z 79 PC: 1342e | Find next file
2018-12-17T22:08:34.634898307Z 59 PC: 13438 | Change current directory
2018-12-17T22:08:34.638879544Z 59 PC: 13516 | Change current directory
2018-12-17T22:08:34.642783242Z 9 PC: 12a86 | Display string (String= 'Goat file (EXE/....). Size=00000BB8h/0000003000d bytes. ')
2018-12-17T22:08:34.648251747Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:08:34.649676746Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:08:34.660616803Z 93 PC: 12afe | File sharing functions
2018-12-17T22:08:34.662805838Z 9 PC: 12a86 | Display string (String= 'Size change=01D5h/00469d. ')
2018-12-17T22:08:34.667830726Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')