Sample viewer

vx.netlux.org/Virus.DOS.Malen.360

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:32.904192659Z 78 PC: 13e8e | Find first file
2018-12-17T23:06:32.913207548Z 61 PC: 13ec8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:32.920496221Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:32.930869122Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:32.933485021Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:32.949003426Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:32.950855558Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:32.95844191Z 62 PC: 13f6c | Close file
2018-12-17T23:06:32.968162555Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:32.971424638Z 61 PC: 13ec8 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:06:32.979247926Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:32.986703463Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:32.988722699Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:32.991889643Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:32.994762033Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:32.997748709Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.00680224Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.010636408Z 61 PC: 13ec8 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:06:33.017751565Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:33.026376009Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:33.03689756Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:33.040409322Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:33.042968353Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:33.049133665Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.05838124Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.061637683Z 61 PC: 13ec8 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:06:33.06909891Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:33.077864199Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:33.080915996Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:33.084111273Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:33.086488633Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:33.089553165Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.098187217Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.102529411Z 61 PC: 13ec8 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:06:33.109830086Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:33.116780964Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:33.120354743Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:33.123522117Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:33.125264202Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:33.129273881Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.140272188Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.143257922Z 61 PC: 13ec8 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:06:33.159715462Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:33.169013132Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:33.173855095Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:33.18242617Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:33.184582533Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:33.192270366Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.201355066Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.205047348Z 61 PC: 13ec8 | Open file (Filename = 'PAH.COM')
2018-12-17T23:06:33.21266526Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:33.220528523Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:33.223744179Z 64 PC: 13f4e | Write file or device (Write 360 bytes on handle 5)
2018-12-17T23:06:33.227123081Z 66 PC: 13f59 | Move file pointer
2018-12-17T23:06:33.229013645Z 64 PC: 13f68 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T23:06:33.233078176Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.242277091Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.245524596Z 61 PC: 13ec8 | Open file (Filename = 'TEST.COM')
2018-12-17T23:06:33.253769527Z 63 PC: 13ed9 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:06:33.257320533Z 66 PC: 13ee4 | Move file pointer
2018-12-17T23:06:33.259301688Z 62 PC: 13f6c | Close file
2018-12-17T23:06:33.261620658Z 79 PC: 13e9c | Find next file
2018-12-17T23:06:33.26627602Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T23:06:33.272361941Z 0 PC: 12a89 | Program terminate