Sample viewer

vx.netlux.org/Virus.DOS.Ministry.474

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:21.710726757Z 71 PC: 21ebf | Get current directory
2018-12-17T21:55:21.714227797Z 59 PC: 21ec7 | Change current directory
2018-12-17T21:55:21.718386998Z 47 PC: 21eeb | Get disk transfer address
2018-12-17T21:55:21.720132157Z 26 PC: 21ef8 | Set disk transfer address
2018-12-17T21:55:21.721740356Z 78 PC: 21f00 | Find first file
2018-12-17T21:55:21.727869737Z 96 PC: 21f2c | Qualify filename
2018-12-17T21:55:21.732497538Z 61 PC: 21f87 | Open file (Filename = 'A:\SLEEP.COM')
2018-12-17T21:55:21.74181363Z 63 PC: 21f95 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:55:21.746572449Z 66 PC: 21fa0 | Move file pointer
2018-12-17T21:55:21.748068384Z 64 PC: 21fcc | Write file or device (Write 474 bytes on handle 5)
2018-12-17T21:55:21.760742586Z 66 PC: 21fde | Move file pointer
2018-12-17T21:55:21.762396571Z 64 PC: 21fea | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:55:21.767216238Z 62 PC: 21ff3 | Close file
2018-12-17T21:55:21.789507227Z 26 PC: 21f70 | Set disk transfer address
2018-12-17T21:55:21.802876855Z 59 PC: 21ed2 | Change current directory
2018-12-17T21:55:21.807257382Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat F400H bytes long ')
2018-12-17T21:55:21.814674803Z 0 PC: 12a89 | Program terminate