Sample viewer

vx.netlux.org/Virus.DOS.Minzdrav.470

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:44.412629198Z 61 PC: 15168 | Open file (Filename = '')
2018-12-17T22:46:44.42174329Z 63 PC: 1517f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:44.425445205Z 62 PC: 15183 | Close file
2018-12-17T22:46:44.427957699Z 78 PC: 151ba | Find first file
2018-12-17T22:46:44.435135779Z 61 PC: 151c4 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:46:44.444148495Z 63 PC: 151d7 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:46:44.452145477Z 66 PC: 151ee | Move file pointer
2018-12-17T22:46:44.454160513Z 64 PC: 15228 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:46:44.458573719Z 66 PC: 1523f | Move file pointer
2018-12-17T22:46:44.460515404Z 64 PC: 1524c | Write file or device (Write 464 bytes on handle 5)
2018-12-17T22:46:44.492677474Z 64 PC: 15261 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:46:44.498483369Z 62 PC: 15265 | Close file
2018-12-17T22:46:44.519854573Z 9 PC: 15146 | Display string (String= ' � From a collection of viruses Sergey Mastykov. � Belarus, 210008, Vitebsk-8, abonent box 6. � Voice/Data V34+ [+375 (0212) 33-14-58] � E-mail � FidoNet (2:453/4.14) ')
2018-12-17T22:46:44.534355657Z 76 PC: 1514a | Terminate with return code (Return code = '36')