Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.291

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:29.711046956Z 26 PC: 12e67 | Set disk transfer address
2018-12-17T21:59:29.713869166Z 53 PC: 12e6c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:29.715015327Z 37 PC: 12e7c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:29.716096329Z 78 PC: 12e89 | Find first file
2018-12-17T21:59:29.722666913Z 61 PC: 12f4e | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:59:29.73401216Z 63 PC: 12e9b | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:59:29.751216398Z 62 PC: 12e9f | Close file
2018-12-17T21:59:29.753318194Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:29.7703744Z 61 PC: 12f4e | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:59:29.777854979Z 64 PC: 12f0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:29.783177608Z 66 PC: 12f15 | Move file pointer
2018-12-17T21:59:29.785524527Z 64 PC: 12f20 | Write file or device (Write 291 bytes on handle 5)
2018-12-17T21:59:29.811939229Z 87 PC: 12f2d | Get or set file date and time
2018-12-17T21:59:29.813973961Z 62 PC: 12f31 | Close file
2018-12-17T21:59:29.822128105Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:29.843196842Z 79 PC: 12e89 | Find next file
2018-12-17T21:59:29.846073978Z 61 PC: 12f4e | Open file (Filename = 'PRINT.COM')
2018-12-17T21:59:29.853290777Z 63 PC: 12e9b | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:59:29.859642993Z 62 PC: 12e9f | Close file
2018-12-17T21:59:29.861743829Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:29.872270968Z 61 PC: 12f4e | Open file (Filename = 'PRINT.COM')
2018-12-17T21:59:29.879223815Z 64 PC: 12f0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:29.882199742Z 66 PC: 12f15 | Move file pointer
2018-12-17T21:59:29.884272843Z 64 PC: 12f20 | Write file or device (Write 291 bytes on handle 5)
2018-12-17T21:59:29.887469993Z 87 PC: 12f2d | Get or set file date and time
2018-12-17T21:59:29.889224205Z 62 PC: 12f31 | Close file
2018-12-17T21:59:29.905582516Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:29.945945219Z 79 PC: 12e89 | Find next file
2018-12-17T21:59:29.948760471Z 61 PC: 12f4e | Open file (Filename = 'HELLO.COM')
2018-12-17T21:59:29.955505143Z 63 PC: 12e9b | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:59:29.977927895Z 62 PC: 12e9f | Close file
2018-12-17T21:59:29.980669865Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:29.990805549Z 61 PC: 12f4e | Open file (Filename = 'HELLO.COM')
2018-12-17T21:59:29.997882886Z 64 PC: 12f0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:30.000955233Z 66 PC: 12f15 | Move file pointer
2018-12-17T21:59:30.002945782Z 64 PC: 12f20 | Write file or device (Write 291 bytes on handle 5)
2018-12-17T21:59:30.006695471Z 87 PC: 12f2d | Get or set file date and time
2018-12-17T21:59:30.008468083Z 62 PC: 12f31 | Close file
2018-12-17T21:59:30.015854652Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:30.025802112Z 79 PC: 12e89 | Find next file
2018-12-17T21:59:30.028373346Z 61 PC: 12f4e | Open file (Filename = 'PHANG.COM')
2018-12-17T21:59:30.035251218Z 63 PC: 12e9b | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:59:30.042455195Z 62 PC: 12e9f | Close file
2018-12-17T21:59:30.044530214Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:30.054382023Z 61 PC: 12f4e | Open file (Filename = 'PHANG.COM')
2018-12-17T21:59:30.061953471Z 64 PC: 12f0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:30.0653096Z 66 PC: 12f15 | Move file pointer
2018-12-17T21:59:30.066966234Z 64 PC: 12f20 | Write file or device (Write 291 bytes on handle 5)
2018-12-17T21:59:30.07056646Z 87 PC: 12f2d | Get or set file date and time
2018-12-17T21:59:30.072622362Z 62 PC: 12f31 | Close file
2018-12-17T21:59:30.080286225Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:30.092279783Z 79 PC: 12e89 | Find next file
2018-12-17T21:59:30.099587758Z 61 PC: 12f4e | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T21:59:30.11975356Z 63 PC: 12e9b | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:59:30.125832077Z 62 PC: 12e9f | Close file
2018-12-17T21:59:30.133942755Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:30.155456416Z 61 PC: 12f4e | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T21:59:30.162481926Z 64 PC: 12f0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:30.166236922Z 66 PC: 12f15 | Move file pointer
2018-12-17T21:59:30.167597746Z 64 PC: 12f20 | Write file or device (Write 291 bytes on handle 5)
2018-12-17T21:59:30.170449102Z 87 PC: 12f2d | Get or set file date and time
2018-12-17T21:59:30.172977152Z 62 PC: 12f31 | Close file
2018-12-17T21:59:30.18060193Z 67 PC: 12f59 | Get or set file attributes
2018-12-17T21:59:30.192193835Z 37 PC: 12ec3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:30.195111333Z 26 PC: 12ecc | Set disk transfer address
2018-12-17T21:59:30.197011608Z 9 PC: 12e3b | Display string (String= 'Generic triage goat. ')
2018-12-17T21:59:30.204699218Z 76 PC: 12e40 | Terminate with return code (Return code = '0')