Sample viewer

vx.netlux.org/Virus.DOS.Shire.210

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:53.136474412Z 53 PC: 12ba6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:53.138594214Z 37 PC: 12bb5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:53.139611827Z 26 PC: 12bbc | Set disk transfer address
2018-12-17T22:39:53.140588276Z 78 PC: 12bc4 | Find first file
2018-12-17T22:39:53.146659655Z 61 PC: 12bd8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:39:53.152692219Z 63 PC: 12be4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:39:53.158428358Z 66 PC: 12bec | Move file pointer
2018-12-17T22:39:53.160071769Z 64 PC: 12c4e | Write file or device (Write 210 bytes on handle 5)
2018-12-17T22:39:53.401217974Z 66 PC: 12c09 | Move file pointer
2018-12-17T22:39:53.402513562Z 64 PC: 12c14 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:39:53.409017526Z 87 PC: 12c22 | Get or set file date and time
2018-12-17T22:39:53.410957841Z 62 PC: 12c26 | Close file
2018-12-17T22:39:53.418444397Z 37 PC: 12c2b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:53.419469725Z 26 PC: 12c4e | Set disk transfer address
2018-12-17T22:39:53.421283704Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:39:53.426428229Z 76 PC: 12a86 | Terminate with return code (Return code = '36')