Sample viewer

vx.netlux.org/Virus.DOS.OGWO.446

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:17.761747024Z 78 PC: 154a2 | Find first file
2018-12-17T23:04:17.770349084Z 61 PC: 154dd | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:17.777739523Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:17.784849315Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:17.787064182Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:17.803729817Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:17.805597832Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:17.813114333Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:17.815596945Z 62 PC: 1555e | Close file
2018-12-17T23:04:17.824486185Z 79 PC: 15571 | Find next file
2018-12-17T23:04:17.827539748Z 61 PC: 154dd | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:17.835616039Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:17.844458526Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:17.846262196Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:17.849880077Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:17.851672941Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:17.854895948Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:17.857529021Z 62 PC: 1555e | Close file
2018-12-17T23:04:17.866229194Z 79 PC: 15571 | Find next file
2018-12-17T23:04:17.869412965Z 61 PC: 154dd | Open file (Filename = 'HELLO.COM')
2018-12-17T23:04:17.877138574Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:17.882134391Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:17.883314206Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:17.892635045Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:17.894744222Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:17.901868985Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:17.903408721Z 62 PC: 1555e | Close file
2018-12-17T23:04:17.912116477Z 79 PC: 15571 | Find next file
2018-12-17T23:04:17.915256231Z 61 PC: 154dd | Open file (Filename = 'PHANG.COM')
2018-12-17T23:04:17.923087614Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:17.931071869Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:17.932976587Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:17.936411752Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:17.939233444Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:17.942138643Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:17.943740671Z 62 PC: 1555e | Close file
2018-12-17T23:04:17.952410198Z 79 PC: 15571 | Find next file
2018-12-17T23:04:17.955405863Z 61 PC: 154dd | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:04:17.962602063Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:17.970461771Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:17.972974262Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:17.975962186Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:17.978428631Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:17.981515323Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:17.983296823Z 62 PC: 1555e | Close file
2018-12-17T23:04:17.991793951Z 79 PC: 15571 | Find next file
2018-12-17T23:04:17.995137627Z 61 PC: 154dd | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:04:18.00290568Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:18.010206962Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:18.013145837Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:18.018153165Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:18.019883554Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:18.023629283Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:18.025446615Z 62 PC: 1555e | Close file
2018-12-17T23:04:18.048161152Z 79 PC: 15571 | Find next file
2018-12-17T23:04:18.051881211Z 61 PC: 154dd | Open file (Filename = 'PAH.COM')
2018-12-17T23:04:18.059144958Z 63 PC: 154ee | Read file or device (Read 13 bytes on handle 5)
2018-12-17T23:04:18.066095036Z 66 PC: 15515 | Move file pointer
2018-12-17T23:04:18.068194401Z 64 PC: 15524 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T23:04:18.071111122Z 66 PC: 15534 | Move file pointer
2018-12-17T23:04:18.072621421Z 64 PC: 15543 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T23:04:18.076025414Z 87 PC: 1555a | Get or set file date and time
2018-12-17T23:04:18.077655489Z 62 PC: 1555e | Close file
2018-12-17T23:04:18.085651282Z 79 PC: 15571 | Find next file
2018-12-17T23:04:18.088544834Z 78 PC: 154a2 | Find first file
2018-12-17T23:04:18.095214368Z 37 PC: 152e6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:18.096255815Z 48 PC: 15186 | Get DOS version
2018-12-17T23:04:18.097327814Z 71 PC: 1519e | Get current directory
2018-12-17T23:04:18.100802976Z 47 PC: 151a9 | Get disk transfer address
2018-12-17T23:04:18.101973373Z 78 PC: 151b9 | Find first file
2018-12-17T23:04:18.109421492Z 67 PC: 1522c | Get or set file attributes
2018-12-17T23:04:18.120387054Z 61 PC: 15233 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:18.127772915Z 63 PC: 15244 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:18.130861617Z 66 PC: 15260 | Move file pointer
2018-12-17T23:04:18.135284517Z 44 PC: 1532b | Get time 0x1532b: call 0x1532e
0x1532e: pop si
0x1532f: sub si, 0x1d4
0x15333: mov word ptr [si], dx
0x15335: add si, 0xe
0x15338: mov di, si
0x1533a: mov cx, 0xcd
0x1533d: xor word ptr [si], dx
0x1533f: add si, 2
0x15342: loop 0x1533d
0x15344: mov ah, 0x40
0x15346: mov bp, dx
0x15348: pop dx
0x15349: mov cx, 0x2dc
0x1534c: int 0xf2
0x1534e: pushf
0x1534f: mov cx, 0xcd
0x15352: xor word ptr [di], bp
0x15354: add di, 2
0x15357: loop 0x15352
2018-12-17T23:04:18.138361972Z 64 PC: 1534e | Write file or device (Write 732 bytes on handle 5)
2018-12-17T23:04:18.149890914Z 66 PC: 1528c | Move file pointer
2018-12-17T23:04:18.152406617Z 64 PC: 15297 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:04:18.155710321Z 87 PC: 152ae | Get or set file date and time
2018-12-17T23:04:18.157632436Z 62 PC: 152b2 | Close file
2018-12-17T23:04:18.167803973Z 67 PC: 152c3 | Get or set file attributes
2018-12-17T23:04:18.172683379Z 59 PC: 151e2 | Change current directory
2018-12-17T23:04:18.177910296Z 37 PC: 152f2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:18.179813615Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-17T23:04:18.182731237Z 76 PC: 12a56 | Terminate with return code (Return code = '0')