Sample viewer

vx.netlux.org/Virus.DOS.MPS.654

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:41.552881978Z 47 PC: 12b14 | Get disk transfer address
2018-12-17T23:10:41.554953795Z 26 PC: 12b2b | Set disk transfer address
2018-12-17T23:10:41.558728155Z 71 PC: 12b36 | Get current directory
2018-12-17T23:10:41.564799777Z 78 PC: 12b4f | Find first file
2018-12-17T23:10:41.5776773Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.594129298Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.597368041Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.600582447Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.611118848Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.614520736Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.617774036Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.621804228Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.626461218Z 79 PC: 12b60 | Find next file
2018-12-17T23:10:41.629462924Z 78 PC: 12c0d | Find first file
2018-12-17T23:10:41.636490324Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:41.654979794Z 61 PC: 12c37 | Open file (Filename = '\SLEEP.COM')
2018-12-17T23:10:41.662692974Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:41.670221125Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:41.673986668Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:41.682629957Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:41.690991195Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:41.732924887Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:41.741989238Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:41.745118895Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:41.756995477Z 61 PC: 12c37 | Open file (Filename = '\PRINT.COM')
2018-12-17T23:10:41.770061685Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:41.777564989Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:41.779997926Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:41.783995466Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:41.78595923Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:41.795118439Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:41.821144938Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:41.824519816Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:41.835924189Z 61 PC: 12c37 | Open file (Filename = '\HELLO.COM')
2018-12-17T23:10:41.844540307Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:41.851827605Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:41.853755972Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:41.857940254Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:41.860031457Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:41.869317565Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:41.878945056Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:41.882383404Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:41.893648424Z 61 PC: 12c37 | Open file (Filename = '\PHANG.COM')
2018-12-17T23:10:41.901380279Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:41.909028586Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:41.910946494Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:41.914234619Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:41.917247677Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:41.92622802Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:41.935392079Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:41.93983685Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:41.951158687Z 61 PC: 12c37 | Open file (Filename = '\PRINTA~1.COM')
2018-12-17T23:10:41.95940553Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:41.971400995Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:41.973762627Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:41.977013553Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:41.979637849Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:41.989864477Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:41.998916053Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:42.002215259Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:42.014163536Z 61 PC: 12c37 | Open file (Filename = '\MANDEL.COM')
2018-12-17T23:10:42.021649958Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:42.029250897Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:42.032218108Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:42.035417937Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:42.037282745Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:42.047616333Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:42.057057854Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:42.060372309Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:42.071938977Z 61 PC: 12c37 | Open file (Filename = '\PAH.COM')
2018-12-17T23:10:42.080033253Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:42.087659589Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:42.089566215Z 64 PC: 12c93 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:42.09388557Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:10:42.095572393Z 64 PC: 12ca5 | Write file or device (Write 654 bytes on handle 5)
2018-12-17T23:10:42.105048108Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:42.115636065Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:42.1189877Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T23:10:42.130006196Z 61 PC: 12c37 | Open file (Filename = '\TEST.COM')
2018-12-17T23:10:42.138228233Z 63 PC: 12c4b | Read file or device (Read 10 bytes on handle 5)
2018-12-17T23:10:42.141587372Z 66 PC: 12c59 | Move file pointer
2018-12-17T23:10:42.143666182Z 62 PC: 12ca9 | Close file
2018-12-17T23:10:42.146520561Z 79 PC: 12cb2 | Find next file
2018-12-17T23:10:42.149736641Z 26 PC: 12cd1 | Set disk transfer address
2018-12-17T23:10:42.151477135Z 9 PC: 12a4b | Display string (String= 'Juliusz Stepinski Marzec 1991 Instalator wirusow. Masz zainstalowanego wirusa COM 654 !!! ')
2018-12-17T23:10:42.161491483Z 76 PC: 12a4f | Terminate with return code (Return code = '36')