Sample viewer

vx.netlux.org/Virus.DOS.Nop.355

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:16:58.136118167Z 26 PC: 12a47 | Set disk transfer address
2018-12-17T22:16:58.137575395Z 78 PC: 12a50 | Find first file
2018-12-17T22:16:58.144106946Z 61 PC: 12a5b | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:16:58.150817114Z 63 PC: 12a6b | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:16:58.157320413Z 62 PC: 12a73 | Close file
2018-12-17T22:16:58.15960203Z 60 PC: 12a9f | Create or truncate file
2018-12-17T22:16:58.177769185Z 64 PC: 12ab1 | Write file or device (Write 355 bytes on handle 5)
2018-12-17T22:16:58.181510671Z 61 PC: 12abc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:16:58.188480682Z 63 PC: 12ad3 | Read file or device (Read 407 bytes on handle 6)
2018-12-17T22:16:58.191279677Z 62 PC: 12ade | Close file
2018-12-17T22:16:58.193266308Z 64 PC: 12af5 | Write file or device (Write 407 bytes on handle 5)
2018-12-17T22:16:58.202342145Z 62 PC: 12b02 | Close file
2018-12-17T22:16:58.210981662Z 65 PC: 12b09 | Delete file (Filename = 'SLEEP.COM')
2018-12-17T22:16:58.223370798Z 86 PC: 12b13 | Rename file
2018-12-17T22:16:58.236116464Z 9 PC: 12b04 | Display string (String= 'Goat file (COM). Size=000000C8h/0000000200d bytes. ')
2018-12-17T22:16:58.240829605Z 76 PC: 12b08 | Terminate with return code (Return code = '36')