Sample viewer

vx.netlux.org/Virus.DOS.Joe.589.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:58.272268375Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:58.273465177Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:58.276053676Z 26 PC: 12cad | Set disk transfer address
2018-12-17T22:54:58.27761935Z 78 PC: 12cb5 | Find first file
2018-12-17T22:54:58.284356153Z 61 PC: 12d6d | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:54:58.292667547Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.299663166Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.302964186Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.318169077Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.319944386Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.327129361Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.336269074Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.339889895Z 61 PC: 12d6d | Open file (Filename = 'PRINT.COM')
2018-12-17T22:54:58.347119584Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.354094885Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.356637177Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.364866798Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.366355819Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.374395942Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.383223497Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.386365858Z 61 PC: 12d6d | Open file (Filename = 'HELLO.COM')
2018-12-17T22:54:58.394774235Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.402882237Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.404789684Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.414930089Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.416617092Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.423535086Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.433268174Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.436689289Z 61 PC: 12d6d | Open file (Filename = 'PHANG.COM')
2018-12-17T22:54:58.443692142Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.450808208Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.452795546Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.460996763Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.462458092Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.471349737Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.48019177Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.483317559Z 61 PC: 12d6d | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:54:58.491149341Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.49855414Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.500085811Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.509443814Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.511125668Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.518061074Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.52890412Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.532309967Z 61 PC: 12d6d | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:54:58.54067396Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.548542281Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.550305668Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.559738902Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.561557352Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.570099711Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.5789241Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.581726301Z 61 PC: 12d6d | Open file (Filename = 'PAH.COM')
2018-12-17T22:54:58.589746648Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.5964353Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.597731218Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:58.611217245Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:58.612771429Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:58.61987434Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.629668523Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.632517542Z 61 PC: 12d6d | Open file (Filename = 'TEST.COM')
2018-12-17T22:54:58.639717295Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.645388272Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:58.647413151Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:58.650230481Z 26 PC: 12cc5 | Set disk transfer address
2018-12-17T22:54:58.652678346Z 37 PC: 12ccc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:58.654012656Z 25 PC: 12c1d | Get default drive
2018-12-17T22:54:58.655149063Z 14 PC: 12c28 | Set default drive (Drive = 'C')
2018-12-17T22:54:58.656638816Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:58.659537218Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:58.660779184Z 26 PC: 12cad | Set disk transfer address
2018-12-17T22:54:58.661881447Z 78 PC: 12cb5 | Find first file
2018-12-17T22:54:58.668818396Z 61 PC: 12d6d | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:54:58.675474326Z 63 PC: 12d8f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:58.679354836Z 66 PC: 12da4 | Move file pointer
2018-12-17T22:54:58.681521692Z 64 PC: 12db0 | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:54:59.685088255Z 66 PC: 12dc6 | Move file pointer
2018-12-17T22:54:59.69403829Z 64 PC: 12dd1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:59.698181754Z 62 PC: 12dd5 | Close file
2018-12-17T22:54:59.708107535Z 79 PC: 12cb5 | Find next file
2018-12-17T22:54:59.711431587Z 26 PC: 12cc5 | Set disk transfer address
2018-12-17T22:54:59.713858593Z 37 PC: 12ccc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:59.715723491Z 14 PC: 12c30 | Set default drive (Drive = 'A')
2018-12-17T22:54:59.717451872Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:54:59.723019815Z 76 PC: 12a86 | Terminate with return code (Return code = '36')