Sample viewer

vx.netlux.org/Virus.DOS.Grfat.550

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:36.064010316Z 26 PC: 13eba | Set disk transfer address
2018-12-17T22:21:36.065554439Z 78 PC: 13ed1 | Find first file
2018-12-17T22:21:36.07425276Z 61 PC: 13f01 | Open file (Filename = 'c:\dos\EDIT.COM')
2018-12-17T22:21:36.082373952Z 63 PC: 13f11 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.088181233Z 66 PC: 13f20 | Move file pointer
2018-12-17T22:21:36.089434247Z 63 PC: 13f2c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.091719753Z 62 PC: 13f32 | Close file
2018-12-17T22:21:36.093920705Z 61 PC: 13f5f | Open file (Filename = 'c:\dos\EDIT.COM')
2018-12-17T22:21:36.100503063Z 64 PC: 13f87 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:21:36.103100794Z 66 PC: 13f92 | Move file pointer
2018-12-17T22:21:36.105207516Z 64 PC: 13fa3 | Write file or device (Write 550 bytes on handle 5)
2018-12-17T22:21:36.461079504Z 87 PC: 13fb0 | Get or set file date and time
2018-12-17T22:21:36.462791413Z 62 PC: 13fb9 | Close file
2018-12-17T22:21:36.469900048Z 79 PC: 13ee4 | Find next file
2018-12-17T22:21:36.473899564Z 61 PC: 13f01 | Open file (Filename = 'c:\dos\FORMAT.COM')
2018-12-17T22:21:36.48176123Z 63 PC: 13f11 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.487727526Z 66 PC: 13f20 | Move file pointer
2018-12-17T22:21:36.490156698Z 63 PC: 13f2c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.498467064Z 62 PC: 13f32 | Close file
2018-12-17T22:21:36.500487291Z 61 PC: 13f5f | Open file (Filename = 'c:\dos\FORMAT.COM')
2018-12-17T22:21:36.508452723Z 64 PC: 13f87 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:21:36.511240946Z 66 PC: 13f92 | Move file pointer
2018-12-17T22:21:36.51260208Z 64 PC: 13fa3 | Write file or device (Write 550 bytes on handle 5)
2018-12-17T22:21:36.520154062Z 87 PC: 13fb0 | Get or set file date and time
2018-12-17T22:21:36.521892134Z 62 PC: 13fb9 | Close file
2018-12-17T22:21:36.53155817Z 79 PC: 13ee4 | Find next file
2018-12-17T22:21:36.535406421Z 61 PC: 13f01 | Open file (Filename = 'c:\dos\KEYB.COM')
2018-12-17T22:21:36.552164205Z 63 PC: 13f11 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.558012618Z 66 PC: 13f20 | Move file pointer
2018-12-17T22:21:36.560597471Z 63 PC: 13f2c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.566258152Z 62 PC: 13f32 | Close file
2018-12-17T22:21:36.568111057Z 61 PC: 13f5f | Open file (Filename = 'c:\dos\KEYB.COM')
2018-12-17T22:21:36.575576069Z 64 PC: 13f87 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:21:36.579345797Z 66 PC: 13f92 | Move file pointer
2018-12-17T22:21:36.581146965Z 64 PC: 13fa3 | Write file or device (Write 550 bytes on handle 5)
2018-12-17T22:21:36.588737939Z 87 PC: 13fb0 | Get or set file date and time
2018-12-17T22:21:36.59033804Z 62 PC: 13fb9 | Close file
2018-12-17T22:21:36.629547826Z 79 PC: 13ee4 | Find next file
2018-12-17T22:21:36.63698138Z 61 PC: 13f01 | Open file (Filename = 'c:\dos\SYS.COM')
2018-12-17T22:21:36.643291636Z 63 PC: 13f11 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.649512503Z 66 PC: 13f20 | Move file pointer
2018-12-17T22:21:36.651351652Z 63 PC: 13f2c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:21:36.658570117Z 62 PC: 13f32 | Close file
2018-12-17T22:21:36.661096994Z 61 PC: 13f5f | Open file (Filename = 'c:\dos\SYS.COM')
2018-12-17T22:21:36.668698499Z 64 PC: 13f87 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:21:36.67236242Z 66 PC: 13f92 | Move file pointer
2018-12-17T22:21:36.674009223Z 64 PC: 13fa3 | Write file or device (Write 550 bytes on handle 5)
2018-12-17T22:21:36.687514812Z 87 PC: 13fb0 | Get or set file date and time
2018-12-17T22:21:36.689976697Z 62 PC: 13fb9 | Close file
2018-12-17T22:21:36.731347152Z 79 PC: 13ee4 | Find next file
2018-12-17T22:21:36.745461134Z 9 PC: 13ff4 | Display string (String= '')
2018-12-17T22:21:36.748144955Z 26 PC: 13ef0 | Set disk transfer address
2018-12-17T22:21:36.750369269Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:21:36.756031398Z 0 PC: 12a89 | Program terminate