Sample viewer

vx.netlux.org/Virus.DOS.Fractal.2979

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:07.623078275Z 62 PC: 13e56 | Close file
2018-12-17T22:32:07.626169759Z 98 PC: 13ec3 | Get current PSP
2018-12-17T22:32:07.627240403Z 202 PC: 13ecc | UNKNOWN!
2018-12-17T22:32:07.628164963Z 74 PC: 13f0a | Reallocate memory
2018-12-17T22:32:07.629842093Z 72 PC: 13f17 | Allocate memory
2018-12-17T22:32:07.633520926Z 61 PC: 9f16c | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:32:07.640131203Z 87 PC: 9f174 | Get or set file date and time
2018-12-17T22:32:07.64152064Z 87 PC: 9f196 | Get or set file date and time
2018-12-17T22:32:07.644174421Z 62 PC: 9f19a | Close file
2018-12-17T22:32:07.997863174Z 53 PC: 9f19f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:07.999533331Z 37 PC: 9f1af | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:08.002225156Z 53 PC: 9f1b4 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:32:08.003692537Z 37 PC: 9f1c4 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:32:08.005788349Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:32:08.011619144Z 0 PC: 12a89 | Program terminate