Sample viewer

vx.netlux.org/Virus.DOS.Findme.608

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:35.518297608Z 78 PC: 13e81 | Find first file
2018-12-17T21:59:35.524874131Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T21:59:35.540696259Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T21:59:35.547169034Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:35.554037364Z 66 PC: 13efd | Move file pointer
2018-12-17T21:59:35.555478766Z 62 PC: 13e8e | Close file
2018-12-17T21:59:35.557172516Z 79 PC: 13e98 | Find next file
2018-12-17T21:59:35.560531288Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T21:59:35.570201327Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T21:59:35.58164509Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:35.588337553Z 66 PC: 13efd | Move file pointer
2018-12-17T21:59:35.58980856Z 62 PC: 13e8e | Close file
2018-12-17T21:59:35.591495361Z 79 PC: 13e98 | Find next file
2018-12-17T21:59:35.595072945Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T21:59:35.604710651Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T21:59:35.611147561Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:35.618303701Z 66 PC: 13efd | Move file pointer
2018-12-17T21:59:35.619789996Z 62 PC: 13e8e | Close file
2018-12-17T21:59:35.621537317Z 79 PC: 13e98 | Find next file
2018-12-17T21:59:35.62441883Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T21:59:35.635076163Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T21:59:35.642608934Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:35.649214521Z 66 PC: 13efd | Move file pointer
2018-12-17T21:59:35.651178277Z 62 PC: 13e8e | Close file
2018-12-17T21:59:35.653150916Z 79 PC: 13e98 | Find next file
2018-12-17T21:59:35.656044324Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T21:59:35.669847463Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T21:59:35.676377048Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:35.682587571Z 66 PC: 13efd | Move file pointer
2018-12-17T21:59:35.685139966Z 62 PC: 13e8e | Close file
2018-12-17T21:59:35.687413013Z 79 PC: 13e98 | Find next file
2018-12-17T21:59:35.690331175Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T21:59:35.700403387Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T21:59:35.706965251Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:35.713656286Z 66 PC: 13efd | Move file pointer
2018-12-17T21:59:35.715793392Z 66 PC: 13f3f | Move file pointer
2018-12-17T21:59:35.717285179Z 63 PC: 13f52 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:35.719871315Z 66 PC: 13f81 | Move file pointer
2018-12-17T21:59:35.722895911Z 64 PC: 13f91 | Write file or device (Write 608 bytes on handle 5)
2018-12-17T21:59:35.731103346Z 66 PC: 13fa3 | Move file pointer
2018-12-17T21:59:35.732617875Z 64 PC: 13fb3 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:35.736463684Z 62 PC: 13fd9 | Close file
2018-12-17T21:59:35.744993905Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T21:59:35.750731366Z 0 PC: 12a89 | Program terminate