Sample viewer

vx.netlux.org/Virus.DOS.AOD.385.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:15.181595163Z 26 PC: 141cf | Set disk transfer address
2018-12-17T23:03:15.183279834Z 78 PC: 14246 | Find first file
2018-12-17T23:03:15.18936925Z 61 PC: 14250 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:03:15.196054907Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.203544065Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.205396879Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.21938979Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.221534192Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.228359109Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.23618234Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.238815221Z 61 PC: 14250 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:03:15.245733334Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.252387366Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.254172711Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.257955303Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.259463213Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.261995751Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.273517021Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.276100389Z 61 PC: 14250 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:03:15.282419931Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.289357594Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.291254801Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.294349352Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.296564278Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.299552525Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.307577076Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.311222557Z 61 PC: 14250 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:03:15.318004423Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.325189333Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.327789106Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.331156358Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.332933071Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.336370743Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.345525024Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.348171018Z 61 PC: 14250 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:03:15.3545571Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.361705361Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.363543659Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.36671303Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.369170626Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.371725642Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.379237331Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.382676918Z 61 PC: 14250 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:03:15.397901582Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.404694902Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.407045438Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.415242379Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.416956809Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.424100125Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.432247169Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.434757966Z 61 PC: 14250 | Open file (Filename = 'PAH.COM')
2018-12-17T23:03:15.441940404Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.448165502Z 66 PC: 14208 | Move file pointer
2018-12-17T23:03:15.44961925Z 64 PC: 14328 | Write file or device (Write 385 bytes on handle 5)
2018-12-17T23:03:15.452478962Z 66 PC: 1421b | Move file pointer
2018-12-17T23:03:15.454496341Z 64 PC: 14226 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:03:15.472717363Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.486828132Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.489546105Z 61 PC: 14250 | Open file (Filename = 'TEST.COM')
2018-12-17T23:03:15.49582361Z 63 PC: 141e8 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.498322293Z 62 PC: 1425b | Close file
2018-12-17T23:03:15.500200475Z 79 PC: 14256 | Find next file
2018-12-17T23:03:15.502542251Z 59 PC: 14269 | Change current directory
2018-12-17T23:03:15.506530016Z 9 PC: 1423b | Display string (String= 'I am the angel of death! and i've come for your computers soul! ha ha ha evil laugh kind of thing!!!!!!!')
2018-12-17T23:03:15.516070106Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/k...). Size=00001770h/0000006000d bytes. ')
2018-12-17T23:03:15.522425198Z 48 PC: 12a8f | Get DOS version
2018-12-17T23:03:15.523548908Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T23:03:15.530564935Z 93 PC: 12afe | File sharing functions
2018-12-17T23:03:15.53237091Z 9 PC: 12a86 | Display string (String= 'Size change=0181h/00385d. ')
2018-12-17T23:03:15.537402074Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')