Sample viewer

vx.netlux.org/Virus.DOS.Devil.941.f

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:57.949922071Z 53 PC: 150d3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:57.951890344Z 78 PC: 15431 | Find first file
2018-12-17T22:50:57.957931007Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:57.973509065Z 61 PC: 153cf | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:50:57.987929904Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:57.994159163Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:57.995712748Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:57.99971532Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.001406789Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.009893499Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.019094819Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.02200676Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.031604458Z 61 PC: 153cf | Open file (Filename = 'PRINT.COM')
2018-12-17T22:50:58.03827594Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.046043309Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.048023514Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.051640998Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.054675669Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.062946269Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.071508048Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.074959536Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.085040533Z 61 PC: 153cf | Open file (Filename = 'HELLO.COM')
2018-12-17T22:50:58.091535967Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.099078533Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.100433504Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.103262919Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.105037255Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.113845416Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.122241947Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.125429738Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.13523646Z 61 PC: 153cf | Open file (Filename = 'PHANG.COM')
2018-12-17T22:50:58.142378757Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.1495536Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.151437319Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.154086111Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.155722694Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.165742975Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.17402545Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.176892909Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.187336655Z 61 PC: 153cf | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:50:58.194154816Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.200687598Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.203140224Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.205705431Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.207047437Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.21624008Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.224547223Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.227464087Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.237975052Z 61 PC: 153cf | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:50:58.2433434Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.247372715Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.249020826Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.250816209Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.251906464Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.257863587Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.265675858Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.268103668Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.280778746Z 61 PC: 153cf | Open file (Filename = 'PAH.COM')
2018-12-17T22:50:58.287151702Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.293212361Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.29497485Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.297389889Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.298609186Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.306669455Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.311857258Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.313671578Z 67 PC: 153c7 | Get or set file attributes
2018-12-17T22:50:58.320793431Z 61 PC: 153cf | Open file (Filename = 'TEST.COM')
2018-12-17T22:50:58.324741779Z 63 PC: 153e1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.329505046Z 66 PC: 153f1 | Move file pointer
2018-12-17T22:50:58.331020863Z 64 PC: 15409 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.332711142Z 66 PC: 15416 | Move file pointer
2018-12-17T22:50:58.333634745Z 64 PC: 1541f | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.339518837Z 62 PC: 15423 | Close file
2018-12-17T22:50:58.347752099Z 79 PC: 1543d | Find next file
2018-12-17T22:50:58.349983358Z 53 PC: 14d26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.351571163Z 78 PC: 15084 | Find first file
2018-12-17T22:50:58.357282778Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.366865318Z 61 PC: 15022 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:50:58.375275438Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.381612778Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.383014033Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.387059714Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.388600675Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.397697767Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.406547344Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.41036212Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.419999238Z 61 PC: 15022 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:50:58.426880823Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.433434733Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.434948464Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.437655367Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.440236813Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.449060775Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.456941232Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.460039824Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.469584008Z 61 PC: 15022 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:50:58.476740865Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.483298124Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.484527093Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.486964079Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.489188132Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.497358399Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.505244387Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.508712992Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.518727973Z 61 PC: 15022 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:50:58.525083645Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.531711535Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.533066955Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.536033264Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.53805943Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.547488601Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.555685452Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.558960656Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.568769665Z 61 PC: 15022 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:50:58.575240559Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.58226543Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.584020769Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.586952271Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.589597182Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.599173072Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.604345392Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.607003806Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.613023851Z 61 PC: 15022 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:50:58.617175822Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.621715025Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.622686684Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.624269008Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.62579009Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.632430064Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.640192623Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.643022915Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.649155131Z 61 PC: 15022 | Open file (Filename = 'PAH.COM')
2018-12-17T22:50:58.655252426Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.662119918Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.663754825Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.666288932Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.668402322Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.677028265Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.684790671Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.688160502Z 67 PC: 1501a | Get or set file attributes
2018-12-17T22:50:58.697868727Z 61 PC: 15022 | Open file (Filename = 'TEST.COM')
2018-12-17T22:50:58.704517289Z 63 PC: 15034 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:58.708231056Z 66 PC: 15044 | Move file pointer
2018-12-17T22:50:58.709837236Z 64 PC: 1505c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:50:58.712783957Z 66 PC: 15069 | Move file pointer
2018-12-17T22:50:58.715327249Z 64 PC: 15072 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:50:58.723825817Z 62 PC: 15076 | Close file
2018-12-17T22:50:58.731875703Z 79 PC: 15090 | Find next file
2018-12-17T22:50:58.734594884Z 74 PC: 14d49 | Reallocate memory
2018-12-17T22:50:58.735878084Z 72 PC: 14d51 | Allocate memory
2018-12-17T22:50:58.737243044Z 53 PC: 14d7f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.738595672Z 37 PC: 14d8f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.740289683Z 53 PC: 14d94 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:50:58.74124767Z 37 PC: 14daf | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:50:58.742805095Z 53 PC: 14979 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.743908917Z 53 PC: 145cc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.745009362Z 53 PC: 1421f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.746645178Z 53 PC: 13e72 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:58.747774295Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:50:58.752950704Z 0 PC: 12a89 | Program terminate