Sample viewer

vx.netlux.org/Virus.DOS.Armen.230.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:45.880764291Z 26 PC: 12a4e | Set disk transfer address
2018-12-17T22:27:45.88280248Z 78 PC: 12a58 | Find first file
2018-12-17T22:27:45.888753994Z 61 PC: 12a64 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:27:45.892896456Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:27:45.900196453Z 66 PC: 12a95 | Move file pointer
2018-12-17T22:27:45.901850675Z 63 PC: 12aa1 | Read file or device (Read 230 bytes on handle 5)
2018-12-17T22:27:45.904513658Z 66 PC: 12aac | Move file pointer
2018-12-17T22:27:45.906461448Z 64 PC: 12ab8 | Write file or device (Write 230 bytes on handle 5)
2018-12-17T22:27:45.920756069Z 66 PC: 12ac1 | Move file pointer
2018-12-17T22:27:45.922025428Z 64 PC: 12acb | Write file or device (Write 230 bytes on handle 5)
2018-12-17T22:27:45.928439424Z 62 PC: 12acf | Close file
2018-12-17T22:27:45.936733148Z 26 PC: 12ad6 | Set disk transfer address
2018-12-17T22:27:45.937848786Z 9 PC: 12add | Display string (String= ' Virus Armenia v.0.3 ')
2018-12-17T22:27:45.943337088Z 9 PC: 12a47 | Display string (String= '�THIS IS A GOAT FILE�-D11nmdc-  [13.03.2002] D11N009.COM > 14.000 (36B0h) ... ')