Sample viewer

vx.netlux.org/Virus.DOS.Findme.695

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:32.291985365Z 78 PC: 13e81 | Find first file
2018-12-17T22:55:32.299555565Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T22:55:32.317836025Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T22:55:32.325707359Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:32.333097819Z 66 PC: 13efd | Move file pointer
2018-12-17T22:55:32.334980203Z 62 PC: 13e8e | Close file
2018-12-17T22:55:32.338502279Z 79 PC: 13e98 | Find next file
2018-12-17T22:55:32.341640454Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T22:55:32.352529317Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T22:55:32.363657381Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:32.378999941Z 66 PC: 13efd | Move file pointer
2018-12-17T22:55:32.380953715Z 62 PC: 13e8e | Close file
2018-12-17T22:55:32.38418641Z 79 PC: 13e98 | Find next file
2018-12-17T22:55:32.387859505Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T22:55:32.399581367Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T22:55:32.407762528Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:32.415775414Z 66 PC: 13efd | Move file pointer
2018-12-17T22:55:32.41782531Z 62 PC: 13e8e | Close file
2018-12-17T22:55:32.421432849Z 79 PC: 13e98 | Find next file
2018-12-17T22:55:32.425593808Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T22:55:32.436581881Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T22:55:32.444043919Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:32.451844961Z 66 PC: 13efd | Move file pointer
2018-12-17T22:55:32.453886877Z 62 PC: 13e8e | Close file
2018-12-17T22:55:32.45631115Z 79 PC: 13e98 | Find next file
2018-12-17T22:55:32.459949493Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T22:55:32.471270512Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T22:55:32.479049413Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:32.488329997Z 66 PC: 13efd | Move file pointer
2018-12-17T22:55:32.490193731Z 62 PC: 13e8e | Close file
2018-12-17T22:55:32.492474274Z 79 PC: 13e98 | Find next file
2018-12-17T22:55:32.49631074Z 67 PC: 13ec5 | Get or set file attributes
2018-12-17T22:55:32.507818885Z 61 PC: 13ed2 | Open file (Filename = '')
2018-12-17T22:55:32.519955911Z 63 PC: 13ee8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:32.528473915Z 66 PC: 13efd | Move file pointer
2018-12-17T22:55:32.533063399Z 66 PC: 13f3f | Move file pointer
2018-12-17T22:55:32.535177894Z 63 PC: 13f52 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:55:32.543373755Z 9 PC: 13f72 | Display string (Could not find end pointer)
2018-12-17T22:55:32.549607807Z 66 PC: 13fac | Move file pointer
2018-12-17T22:55:32.551289614Z 64 PC: 13fbc | Write file or device (Write 695 bytes on handle 5)
2018-12-17T22:55:32.569176459Z 66 PC: 13fce | Move file pointer
2018-12-17T22:55:32.571956689Z 64 PC: 13fde | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:55:32.575519636Z 62 PC: 14004 | Close file
2018-12-17T22:55:32.585280181Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:55:32.592662212Z 0 PC: 12a89 | Program terminate