Sample viewer

vx.netlux.org/Virus.DOS.Vgpsi.193

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:03.321712607Z 78 PC: 12a7c | Find first file
2018-12-17T23:01:03.328222528Z 61 PC: 12af9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:01:03.335252209Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.343100038Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.349910397Z 61 PC: 12af9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:01:03.358366043Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.361352059Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.363483896Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.366069049Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.367374057Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.388852236Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.396598742Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.399180217Z 61 PC: 12af9 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:01:03.405962031Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.412055167Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.413724251Z 61 PC: 12af9 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:01:03.420445207Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.422812756Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.424067429Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.426937313Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.42832486Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.43090798Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.439143155Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.441671014Z 61 PC: 12af9 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:01:03.453852179Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.46139534Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.464799372Z 61 PC: 12af9 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:01:03.471531664Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.474895235Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.476574267Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.479325145Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.481754018Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.48439738Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.492007221Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.495261587Z 61 PC: 12af9 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:01:03.501754185Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.50835716Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.520351553Z 61 PC: 12af9 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:01:03.527303413Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.530907724Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.534436498Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.537544936Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.539183765Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.543115005Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.55184662Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.555102699Z 61 PC: 12af9 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:01:03.563132993Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.569751247Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.571912799Z 61 PC: 12af9 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:01:03.57956897Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.582722868Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.584378902Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.588017483Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.589603754Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.592462561Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.60105364Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.604662985Z 61 PC: 12af9 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:01:03.611335176Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.618252418Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.620354707Z 61 PC: 12af9 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:01:03.627117219Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.630708073Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.632054902Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.635292922Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.637248095Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.645656475Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.655109999Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.658806694Z 61 PC: 12af9 | Open file (Filename = 'PAH.COM')
2018-12-17T23:01:03.66698075Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.674064669Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.677006092Z 61 PC: 12af9 | Open file (Filename = 'PAH.COM')
2018-12-17T23:01:03.684159737Z 63 PC: 12ac5 | Read file or device (Read 193 bytes on handle 5)
2018-12-17T23:01:03.68714121Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.689294352Z 64 PC: 12ad4 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.692030429Z 66 PC: 12aee | Move file pointer
2018-12-17T23:01:03.693738878Z 64 PC: 12ae2 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T23:01:03.697822682Z 62 PC: 12ae6 | Close file
2018-12-17T23:01:03.70556126Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.708272724Z 61 PC: 12af9 | Open file (Filename = 'TEST.COM')
2018-12-17T23:01:03.715499059Z 63 PC: 12a95 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:01:03.721679918Z 62 PC: 12a99 | Close file
2018-12-17T23:01:03.723658333Z 79 PC: 12a7c | Find next file
2018-12-17T23:01:03.726483977Z 80 PC: 13fb9 | Set current PSP
2018-12-17T23:01:03.727772163Z 48 PC: 13fbe | Get DOS version
2018-12-17T23:01:03.729229911Z 99 PC: 1a7a0 | Get DBCS lead byte table pointer
2018-12-17T23:01:03.731878073Z 101 PC: 14044 | Get extended country info
2018-12-17T23:01:03.733614026Z 99 PC: 1404a | Get DBCS lead byte table pointer
2018-12-17T23:01:03.734802776Z 74 PC: 140ac | Reallocate memory
2018-12-17T23:01:03.736117797Z 25 PC: 140e3 | Get default drive
2018-12-17T23:01:03.737776343Z 37 PC: 13ba3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:01:03.738787491Z 37 PC: 13baa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:03.739795709Z 37 PC: 13bb1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:03.742804957Z 61 PC: 142ba | Open file
2018-12-17T23:01:03.747951838Z 72 PC: 1492d | Allocate memory
2018-12-17T23:01:03.749942136Z 61 PC: 143a9 | Open file (Filename = '?\COMMAND.COM')
2018-12-17T23:01:03.754995043Z 89 PC: 1836c | Get extended error info
2018-12-17T23:01:03.75639582Z 2 PC: 13e6c | Character output (Char = '53')
2018-12-17T23:01:03.758573839Z 2 PC: 13e6c | Character output (Char = '70')
2018-12-17T23:01:03.761201373Z 2 PC: 13e6c | Character output (Char = '65')
2018-12-17T23:01:03.763327093Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T23:01:03.765574172Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:03.768313493Z 2 PC: 13e6c | Character output (Char = '66')
2018-12-17T23:01:03.770490246Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:03.772643787Z 2 PC: 13e6c | Character output (Char = '65')
2018-12-17T23:01:03.775196148Z 2 PC: 13e6c | Character output (Char = '64')
2018-12-17T23:01:03.777123977Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.779020881Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T23:01:03.781613881Z 2 PC: 13e6c | Character output (Char = '4f')
2018-12-17T23:01:03.783511307Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T23:01:03.785422537Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T23:01:03.788039007Z 2 PC: 13e6c | Character output (Char = '41')
2018-12-17T23:01:03.790091475Z 2 PC: 13e6c | Character output (Char = '4e')
2018-12-17T23:01:03.792124059Z 2 PC: 13e6c | Character output (Char = '44')
2018-12-17T23:01:03.79481427Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.797182817Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T23:01:03.799076914Z 2 PC: 13e6c | Character output (Char = '65')
2018-12-17T23:01:03.802031719Z 2 PC: 13e6c | Character output (Char = '61')
2018-12-17T23:01:03.804089044Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:03.806592593Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T23:01:03.809730227Z 2 PC: 13e6c | Character output (Char = '68')
2018-12-17T23:01:03.811917487Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.814202234Z 2 PC: 13e6c | Character output (Char = '64')
2018-12-17T23:01:03.817333219Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:03.81944369Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:03.821460421Z 2 PC: 13e6c | Character output (Char = '65')
2018-12-17T23:01:03.824060048Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T23:01:03.82705923Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T23:01:03.829303767Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:03.832680982Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:03.834857721Z 2 PC: 13e6c | Character output (Char = '79')
2018-12-17T23:01:03.837175803Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.840017681Z 2 PC: 13e6c | Character output (Char = '62')
2018-12-17T23:01:03.84237188Z 2 PC: 13e6c | Character output (Char = '61')
2018-12-17T23:01:03.845665866Z 2 PC: 13e6c | Character output (Char = '64')
2018-12-17T23:01:03.848895859Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T23:01:03.85086852Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T23:01:03.855893221Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T23:01:03.857923555Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T23:01:03.861499163Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T23:01:03.865610299Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T23:01:03.875120662Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T23:01:03.878708275Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:03.88122612Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T23:01:03.88334187Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:03.885323828Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:03.887681095Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T23:01:03.889701938Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:03.89172667Z 2 PC: 13e6c | Character output (Char = '66')
2018-12-17T23:01:03.894611274Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T23:01:03.897069172Z 2 PC: 13e6c | Character output (Char = '28')
2018-12-17T23:01:03.899104812Z 2 PC: 13e6c | Character output (Char = '52')
2018-12-17T23:01:03.901693139Z 2 PC: 13e6c | Character output (Char = '29')
2018-12-17T23:01:03.903925607Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.90971662Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T23:01:03.913685572Z 2 PC: 13e6c | Character output (Char = '53')
2018-12-17T23:01:03.915958224Z 2 PC: 13e6c | Character output (Char = '2d')
2018-12-17T23:01:03.919727785Z 2 PC: 13e6c | Character output (Char = '44')
2018-12-17T23:01:03.923016175Z 2 PC: 13e6c | Character output (Char = '4f')
2018-12-17T23:01:03.925268542Z 2 PC: 13e6c | Character output (Char = '53')
2018-12-17T23:01:03.927364404Z 2 PC: 13e6c | Character output (Char = '28')
2018-12-17T23:01:03.942806684Z 2 PC: 13e6c | Character output (Char = '52')
2018-12-17T23:01:03.945242956Z 2 PC: 13e6c | Character output (Char = '29')
2018-12-17T23:01:03.947187398Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.94945728Z 2 PC: 13e6c | Character output (Char = '56')
2018-12-17T23:01:03.951592234Z 2 PC: 13e6c | Character output (Char = '65')
2018-12-17T23:01:03.954431802Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:03.957609333Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T23:01:03.959621463Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:03.961532071Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:03.96451312Z 2 PC: 13e6c | Character output (Char = '6e')
2018-12-17T23:01:03.966542375Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.975111319Z 2 PC: 13e6c | Character output (Char = '36')
2018-12-17T23:01:03.977782937Z 2 PC: 13e6c | Character output (Char = '2e')
2018-12-17T23:01:03.97973164Z 2 PC: 13e6c | Character output (Char = '32')
2018-12-17T23:01:03.981775336Z 2 PC: 13e6c | Character output (Char = '32')
2018-12-17T23:01:03.985119553Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T23:01:03.986908029Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T23:01:03.990274678Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.992534912Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.995148498Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:03.998081365Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.000817964Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.002859985Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.004919508Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.007233059Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.009443422Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.011700521Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.015214994Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.017873217Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.020726422Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.022945717Z 2 PC: 13e6c | Character output (Char = '28')
2018-12-17T23:01:04.025172383Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T23:01:04.028243264Z 2 PC: 13e6c | Character output (Char = '29')
2018-12-17T23:01:04.030274959Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T23:01:04.032477594Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:04.035357715Z 2 PC: 13e6c | Character output (Char = '70')
2018-12-17T23:01:04.037342802Z 2 PC: 13e6c | Character output (Char = '79')
2018-12-17T23:01:04.039314275Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:04.042197512Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:04.044092014Z 2 PC: 13e6c | Character output (Char = '67')
2018-12-17T23:01:04.045988901Z 2 PC: 13e6c | Character output (Char = '68')
2018-12-17T23:01:04.04830925Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T23:01:04.050691764Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.052732336Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T23:01:04.05527685Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T23:01:04.058715354Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T23:01:04.060729736Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:04.062792544Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:04.064758165Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T23:01:04.06681286Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:04.0690203Z 2 PC: 13e6c | Character output (Char = '66')
2018-12-17T23:01:04.070903947Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T23:01:04.073678307Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.07676485Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T23:01:04.079313952Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T23:01:04.082669983Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T23:01:04.085112693Z 2 PC: 13e6c | Character output (Char = '70')
2018-12-17T23:01:04.08873986Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T23:01:04.091569771Z 2 PC: 13e6c | Character output (Char = '31')
2018-12-17T23:01:04.093949009Z 2 PC: 13e6c | Character output (Char = '39')
2018-12-17T23:01:04.096243951Z 2 PC: 13e6c | Character output (Char = '38')
2018-12-17T23:01:04.09954446Z 2 PC: 13e6c | Character output (Char = '31')
2018-12-17T23:01:04.10184756Z 2 PC: 13e6c | Character output (Char = '2d')
2018-12-17T23:01:04.104112157Z 2 PC: 13e6c | Character output (Char = '31')
2018-12-17T23:01:04.10735993Z 2 PC: 13e6c | Character output (Char = '39')
2018-12-17T23:01:04.109632398Z 2 PC: 13e6c | Character output (Char = '39')
2018-12-17T23:01:04.1119826Z 2 PC: 13e6c | Character output (Char = '34')
2018-12-17T23:01:04.115638789Z 2 PC: 13e6c | Character output (Char = '2e')
2018-12-17T23:01:04.117978718Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T23:01:04.119807914Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T23:01:04.124228374Z 74 PC: 12d4c | Reallocate memory
2018-12-17T23:01:04.125571456Z 72 PC: 12d8d | Allocate memory
2018-12-17T23:01:04.127237125Z 73 PC: 12daf | Release memory
2018-12-17T23:01:04.128926618Z 72 PC: 12dc5 | Allocate memory
2018-12-17T23:01:04.132104865Z 72 PC: 12dcd | Allocate memory