Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Gandalf.325

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:50:49.104486506Z 71 PC: 12a54 | Get current directory
2018-12-17T21:50:49.108216691Z 26 PC: 12a5c | Set disk transfer address
2018-12-17T21:50:49.109662226Z 53 PC: 12a61 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:49.111100272Z 37 PC: 12a6c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:49.11253754Z 78 PC: 12abe | Find first file
2018-12-17T21:50:49.11928596Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.125072966Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.141655019Z 61 PC: 12ade | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:50:49.154254388Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.15595319Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.16253302Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.16484215Z 64 PC: 12b3c | Write file or device (Write 325 bytes on handle 5)
2018-12-17T21:50:49.173125474Z 66 PC: 12b45 | Move file pointer
2018-12-17T21:50:49.174860331Z 64 PC: 12b50 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:50:49.182575896Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.184487884Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.193024172Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.203542399Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.206526598Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.212094678Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.22844982Z 61 PC: 12ade | Open file (Filename = 'PRINT.COM')
2018-12-17T21:50:49.235161052Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.236817049Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.243881774Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.245433115Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.246876311Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.254201198Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.264698069Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.267557674Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.273740461Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.286597194Z 61 PC: 12ade | Open file (Filename = 'HELLO.COM')
2018-12-17T21:50:49.293391521Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.295280884Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.302172354Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.303596771Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.305485617Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.313115523Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.322992717Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.325903744Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.332287737Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.347001221Z 61 PC: 12ade | Open file (Filename = 'PHANG.COM')
2018-12-17T21:50:49.353857592Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.355786368Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.362316679Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.364126Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.366865908Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.374930708Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.384759265Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.388596818Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.400964449Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.413368414Z 61 PC: 12ade | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T21:50:49.421129405Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.423471729Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.429850922Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.432527697Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.433984818Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.440924703Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.452240007Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.455105328Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.461018136Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.471790891Z 61 PC: 12ade | Open file (Filename = 'MANDEL.COM')
2018-12-17T21:50:49.484079994Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.485772677Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.492694291Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.494670276Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.496311915Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.501706704Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.510136552Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.51192336Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.516143426Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.523425503Z 61 PC: 12ade | Open file (Filename = 'PAH.COM')
2018-12-17T21:50:49.532266108Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.533548967Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.538742538Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.540092643Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.542111015Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.552559277Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.559585331Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.569484908Z 67 PC: 12ac9 | Get or set file attributes
2018-12-17T21:50:49.575960769Z 67 PC: 12ad5 | Get or set file attributes
2018-12-17T21:50:49.585790785Z 61 PC: 12ade | Open file (Filename = 'TEST.COM')
2018-12-17T21:50:49.592633327Z 87 PC: 12ae5 | Get or set file date and time
2018-12-17T21:50:49.594903843Z 63 PC: 12af2 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:50:49.601365553Z 66 PC: 12afa | Move file pointer
2018-12-17T21:50:49.603089858Z 87 PC: 12b5b | Get or set file date and time
2018-12-17T21:50:49.605910932Z 62 PC: 12b5f | Close file
2018-12-17T21:50:49.615761561Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T21:50:49.625767103Z 79 PC: 12abe | Find next file
2018-12-17T21:50:49.629387359Z 59 PC: 12a93 | Change current directory
2018-12-17T21:50:49.633709413Z 59 PC: 12aa2 | Change current directory
2018-12-17T21:50:49.638047441Z 37 PC: 12aa9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:49.640224183Z 26 PC: 12ab0 | Set disk transfer address