Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Iris.567

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:52.386754656Z 53 PC: 14037 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:52.393481364Z 53 PC: 14037 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:52.399593087Z 37 PC: 14037 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:52.400997025Z 26 PC: 14037 | Set disk transfer address
2018-12-17T22:59:52.402352347Z 78 PC: 14037 | Find first file
2018-12-17T22:59:52.409824769Z 61 PC: 14037 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:52.418304624Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.425802936Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.428448011Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.631635374Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.6342667Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.642901333Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.652871909Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.656315078Z 61 PC: 14037 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:59:52.664979209Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.67401697Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.677257271Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.687372293Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.690353424Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.699105331Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.708589657Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.712373308Z 61 PC: 14037 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:59:52.720268598Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.727978875Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.730355242Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.739895685Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.741756815Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.750533348Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.760601654Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.764002476Z 61 PC: 14037 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:59:52.772786634Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.780252939Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.782310843Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.791838972Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.79429083Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.801821054Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.811597904Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.829112878Z 61 PC: 14037 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:59:52.836936865Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.844101904Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.846467101Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.855566529Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.857491053Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.866244915Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.876681112Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.880107796Z 61 PC: 14037 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:59:52.888558008Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.896394603Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.898815011Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.909057453Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.911655344Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.920215613Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.931109468Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.937506757Z 61 PC: 14037 | Open file (Filename = 'PAH.COM')
2018-12-17T22:59:52.945314497Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:52.953020411Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.955971433Z 64 PC: 14037 | Write file or device (Write 567 bytes on handle 5)
2018-12-17T22:59:52.965493847Z 66 PC: 14037 | Move file pointer
2018-12-17T22:59:52.967526878Z 64 PC: 14037 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:59:52.97606921Z 62 PC: 14037 | Close file
2018-12-17T22:59:52.9860594Z 79 PC: 14037 | Find next file
2018-12-17T22:59:52.989381426Z 61 PC: 14037 | Open file (Filename = 'TEST.COM')
2018-12-17T22:59:52.997774368Z 63 PC: 14037 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:59:53.002985927Z 62 PC: 14037 | Close file
2018-12-17T22:59:53.005072833Z 79 PC: 14037 | Find next file
2018-12-17T22:59:53.008016733Z 26 PC: 14037 | Set disk transfer address
2018-12-17T22:59:53.010534515Z 37 PC: 14037 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:53.012235185Z 37 PC: 14037 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:53.013923046Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:59:53.021321817Z 0 PC: 12a89 | Program terminate