Sample viewer

vx.netlux.org/Virus.DOS.Companion.Nucleii.587

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:37.401931132Z 65 PC: 12a80 | Delete file (Filename = 'n.com')
2018-12-17T23:08:37.409753519Z 78 PC: 12ab5 | Find first file
2018-12-17T23:08:37.422493613Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.427810754Z 61 PC: 12aec | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:08:37.435340938Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 5)
2018-12-17T23:08:37.443483682Z 62 PC: 12afc | Close file
2018-12-17T23:08:37.445595168Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:37.546926927Z 61 PC: 12b23 | Open file (Filename = 'SLEEP.bat')
2018-12-17T23:08:37.557331924Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 6)
2018-12-17T23:08:37.566494794Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 6)
2018-12-17T23:08:37.569409564Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 6)
2018-12-17T23:08:37.573407868Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 6)
2018-12-17T23:08:37.577017875Z 62 PC: 12b67 | Close file
2018-12-17T23:08:37.586211929Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:37.596194509Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.606627774Z 61 PC: 12aec | Open file (Filename = 'PRINT.COM')
2018-12-17T23:08:37.615073172Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 6)
2018-12-17T23:08:37.622413002Z 62 PC: 12afc | Close file
2018-12-17T23:08:37.625221216Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:37.638119581Z 61 PC: 12b23 | Open file (Filename = 'PRINT.bat')
2018-12-17T23:08:37.645681051Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 7)
2018-12-17T23:08:37.655321449Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 7)
2018-12-17T23:08:37.658345381Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 7)
2018-12-17T23:08:37.661295059Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 7)
2018-12-17T23:08:37.664955953Z 62 PC: 12b67 | Close file
2018-12-17T23:08:37.674591572Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:37.677582359Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.684546648Z 61 PC: 12aec | Open file (Filename = 'HELLO.COM')
2018-12-17T23:08:37.69190053Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 7)
2018-12-17T23:08:37.698866086Z 62 PC: 12afc | Close file
2018-12-17T23:08:37.701310595Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:37.71332269Z 61 PC: 12b23 | Open file (Filename = 'HELLO.bat')
2018-12-17T23:08:37.720943833Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 8)
2018-12-17T23:08:37.730225829Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 8)
2018-12-17T23:08:37.734001917Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 8)
2018-12-17T23:08:37.737866569Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 8)
2018-12-17T23:08:37.740854463Z 62 PC: 12b67 | Close file
2018-12-17T23:08:37.750086243Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:37.753123559Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.759702857Z 61 PC: 12aec | Open file (Filename = 'PHANG.COM')
2018-12-17T23:08:37.769030312Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 8)
2018-12-17T23:08:37.776306338Z 62 PC: 12afc | Close file
2018-12-17T23:08:37.778654509Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:37.792946437Z 61 PC: 12b23 | Open file (Filename = 'PHANG.bat')
2018-12-17T23:08:37.800452696Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 9)
2018-12-17T23:08:37.809642881Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 9)
2018-12-17T23:08:37.812942832Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 9)
2018-12-17T23:08:37.815897584Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 9)
2018-12-17T23:08:37.818709022Z 62 PC: 12b67 | Close file
2018-12-17T23:08:37.828685737Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:37.832260097Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.839343076Z 61 PC: 12aec | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:08:37.846798535Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 9)
2018-12-17T23:08:37.854776255Z 62 PC: 12afc | Close file
2018-12-17T23:08:37.856826877Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:37.869457425Z 61 PC: 12b23 | Open file (Filename = 'PRINTA~1.bat')
2018-12-17T23:08:37.878237911Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 10)
2018-12-17T23:08:37.887583399Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 10)
2018-12-17T23:08:37.890877962Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 10)
2018-12-17T23:08:37.895101834Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 10)
2018-12-17T23:08:37.89886055Z 62 PC: 12b67 | Close file
2018-12-17T23:08:37.908111047Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:37.912000165Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.919628441Z 61 PC: 12aec | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:08:37.927105644Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 10)
2018-12-17T23:08:37.934509713Z 62 PC: 12afc | Close file
2018-12-17T23:08:37.937465733Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:37.949238469Z 61 PC: 12b23 | Open file (Filename = 'MANDEL.bat')
2018-12-17T23:08:37.956859097Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 11)
2018-12-17T23:08:37.966844215Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 11)
2018-12-17T23:08:37.970250941Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 11)
2018-12-17T23:08:37.973661629Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 11)
2018-12-17T23:08:37.977918258Z 62 PC: 12b67 | Close file
2018-12-17T23:08:37.985538852Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:37.987510527Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:37.992292003Z 61 PC: 12aec | Open file (Filename = 'PAH.COM')
2018-12-17T23:08:38.005842579Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 11)
2018-12-17T23:08:38.013159142Z 62 PC: 12afc | Close file
2018-12-17T23:08:38.015449232Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:38.029048256Z 61 PC: 12b23 | Open file (Filename = 'PAH.bat')
2018-12-17T23:08:38.037006341Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 12)
2018-12-17T23:08:38.046710152Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 12)
2018-12-17T23:08:38.051464086Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 12)
2018-12-17T23:08:38.054870165Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 12)
2018-12-17T23:08:38.058298203Z 62 PC: 12b67 | Close file
2018-12-17T23:08:38.06939111Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:38.07482569Z 67 PC: 12ae4 | Get or set file attributes
2018-12-17T23:08:38.081755907Z 61 PC: 12aec | Open file (Filename = 'TEST.COM')
2018-12-17T23:08:38.090187277Z 63 PC: 12af8 | Read file or device (Read 68 bytes on handle 12)
2018-12-17T23:08:38.098329132Z 62 PC: 12afc | Close file
2018-12-17T23:08:38.101458415Z 60 PC: 12b1b | Create or truncate file
2018-12-17T23:08:38.115190178Z 61 PC: 12b23 | Open file (Filename = 'TEST.bat')
2018-12-17T23:08:38.129466495Z 64 PC: 12b2e | Write file or device (Write 566 bytes on handle 13)
2018-12-17T23:08:38.139448144Z 64 PC: 12b4f | Write file or device (Write 14 bytes on handle 13)
2018-12-17T23:08:38.143833441Z 64 PC: 12b59 | Write file or device (Write 2 bytes on handle 13)
2018-12-17T23:08:38.147986617Z 64 PC: 12b63 | Write file or device (Write 5 bytes on handle 13)
2018-12-17T23:08:38.151393033Z 62 PC: 12b67 | Close file
2018-12-17T23:08:38.161683259Z 79 PC: 12b6b | Find next file
2018-12-17T23:08:38.165073294Z 60 PC: 12ac0 | Create or truncate file
2018-12-17T23:08:38.177478438Z 61 PC: 12ac8 | Open file (Filename = 'n.com')
2018-12-17T23:08:38.185832196Z 64 PC: 12ad2 | Write file or device (Write 145 bytes on handle 13)
2018-12-17T23:08:38.191450702Z 62 PC: 12ad6 | Close file
2018-12-17T23:08:38.201549485Z 76 PC: 12adb | Terminate with return code (Return code = '0')