Sample viewer

vx.netlux.org/Virus.DOS.V.439.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:51.995612072Z 26 PC: 12a4d | Set disk transfer address
2018-12-17T22:19:52.009603788Z 78 PC: 12a7d | Find first file
2018-12-17T22:19:52.015062704Z 61 PC: 12a8a | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:19:52.019696092Z 87 PC: 12a9b | Get or set file date and time
2018-12-17T22:19:52.021195704Z 63 PC: 12ab1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:52.025037669Z 66 PC: 12adf | Move file pointer
2018-12-17T22:19:52.026044617Z 63 PC: 12af4 | Read file or device (Read 64000 bytes on handle 5)
2018-12-17T22:19:52.027999956Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:19:52.029039475Z 64 PC: 12b27 | Write file or device (Write 846 bytes on handle 5)
2018-12-17T22:19:52.040361241Z 87 PC: 12b4b | Get or set file date and time
2018-12-17T22:19:52.042584794Z 62 PC: 12b53 | Close file
2018-12-17T22:19:52.050923998Z 79 PC: 12b61 | Find next file
2018-12-17T22:19:52.053461583Z 61 PC: 12a8a | Open file (Filename = 'PRINT.COM')
2018-12-17T22:19:52.059763375Z 87 PC: 12a9b | Get or set file date and time
2018-12-17T22:19:52.061316216Z 63 PC: 12ab1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:52.068171134Z 66 PC: 12adf | Move file pointer
2018-12-17T22:19:52.069489114Z 63 PC: 12af4 | Read file or device (Read 64000 bytes on handle 5)
2018-12-17T22:19:52.071584372Z 62 PC: 12acf | Close file
2018-12-17T22:19:52.072814322Z 79 PC: 12b61 | Find next file
2018-12-17T22:19:52.074549824Z 61 PC: 12a8a | Open file (Filename = 'HELLO.COM')
2018-12-17T22:19:52.079282983Z 87 PC: 12a9b | Get or set file date and time
2018-12-17T22:19:52.080457617Z 63 PC: 12ab1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:52.084334099Z 66 PC: 12adf | Move file pointer
2018-12-17T22:19:52.09776996Z 63 PC: 12af4 | Read file or device (Read 64000 bytes on handle 5)
2018-12-17T22:19:52.103513194Z 62 PC: 12acf | Close file
2018-12-17T22:19:52.105168737Z 79 PC: 12b61 | Find next file
2018-12-17T22:19:52.108602787Z 61 PC: 12a8a | Open file (Filename = 'PHANG.COM')
2018-12-17T22:19:52.11498661Z 87 PC: 12a9b | Get or set file date and time
2018-12-17T22:19:52.116229298Z 63 PC: 12ab1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:52.124236252Z 66 PC: 12adf | Move file pointer
2018-12-17T22:19:52.126110485Z 63 PC: 12af4 | Read file or device (Read 64000 bytes on handle 5)
2018-12-17T22:19:52.129689765Z 62 PC: 12acf | Close file
2018-12-17T22:19:52.132857914Z 79 PC: 12b61 | Find next file
2018-12-17T22:19:52.135814521Z 61 PC: 12a8a | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:19:52.14262272Z 87 PC: 12a9b | Get or set file date and time
2018-12-17T22:19:52.145143107Z 63 PC: 12ab1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:52.151661717Z 66 PC: 12adf | Move file pointer
2018-12-17T22:19:52.153339382Z 63 PC: 12af4 | Read file or device (Read 64000 bytes on handle 5)
2018-12-17T22:19:52.156070977Z 62 PC: 12acf | Close file
2018-12-17T22:19:52.15824411Z 79 PC: 12b61 | Find next file
2018-12-17T22:19:52.161082517Z 61 PC: 12a8a | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:19:52.169196609Z 87 PC: 12a9b | Get or set file date and time
2018-12-17T22:19:52.171149979Z 63 PC: 12ab1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:52.178318966Z 66 PC: 12adf | Move file pointer
2018-12-17T22:19:52.17986082Z 63 PC: 12af4 | Read file or device (Read 64000 bytes on handle 5)
2018-12-17T22:19:52.183165402Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:19:52.184646611Z 64 PC: 12b27 | Write file or device (Write 940 bytes on handle 5)
2018-12-17T22:19:52.192851193Z 87 PC: 12b4b | Get or set file date and time
2018-12-17T22:19:52.19555325Z 62 PC: 12b53 | Close file
2018-12-17T22:19:52.205621705Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T22:19:52.211491Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:19:52.214453859Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:19:52.221167134Z 93 PC: 12afe | File sharing functions
2018-12-17T22:19:52.223705087Z 9 PC: 12a86 | Display string (String= 'Size change=01B7h/00439d. ')
2018-12-17T22:19:52.228946058Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')