Sample viewer

vx.netlux.org/Virus.DOS.Grog.926

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:43.571635912Z 53 PC: 12fca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:43.573140063Z 37 PC: 12fd7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:43.575039373Z 26 PC: 12fde | Set disk transfer address
2018-12-17T22:30:43.576316424Z 78 PC: 12fe6 | Find first file
2018-12-17T22:30:43.583871172Z 61 PC: 130fc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:30:43.597335725Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.605262284Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.608073818Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.624138411Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.625272752Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.629483807Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.637016372Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.639864083Z 61 PC: 130fc | Open file (Filename = 'PRINT.COM')
2018-12-17T22:30:43.64730955Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.65448213Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.656090407Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.662695195Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.664524605Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.671666943Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.681733914Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.686014246Z 61 PC: 130fc | Open file (Filename = 'HELLO.COM')
2018-12-17T22:30:43.695315071Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.703723855Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.706803384Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.718089428Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.720191679Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.728152119Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.738707944Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.74207541Z 61 PC: 130fc | Open file (Filename = 'PHANG.COM')
2018-12-17T22:30:43.750122963Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.759338426Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.762111879Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.772433388Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.774465134Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.782562713Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.792210202Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.79561922Z 61 PC: 130fc | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:30:43.804308571Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.811845185Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.814508677Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.824819689Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.82679747Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.834927812Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.845443455Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.848996691Z 61 PC: 130fc | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:30:43.858177719Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.867238891Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.869719668Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.879664312Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.881781191Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.88931212Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.899628721Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.903300909Z 61 PC: 130fc | Open file (Filename = 'PAH.COM')
2018-12-17T22:30:43.912541849Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.920526698Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:43.923545143Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:43.934401899Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:43.936477446Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:43.944206702Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.954262824Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.957272034Z 61 PC: 130fc | Open file (Filename = 'TEST.COM')
2018-12-17T22:30:43.964660782Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:43.96964998Z 62 PC: 1316b | Close file
2018-12-17T22:30:43.972204775Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:43.975637743Z 26 PC: 12ff6 | Set disk transfer address
2018-12-17T22:30:43.977720648Z 37 PC: 12ffd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:43.980007042Z 25 PC: 12f76 | Get default drive
2018-12-17T22:30:43.981580815Z 14 PC: 12f81 | Set default drive (Drive = 'C')
2018-12-17T22:30:43.983331006Z 53 PC: 12fca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:43.989264481Z 37 PC: 12fd7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:43.990736576Z 26 PC: 12fde | Set disk transfer address
2018-12-17T22:30:43.991967339Z 78 PC: 12fe6 | Find first file
2018-12-17T22:30:43.9990929Z 61 PC: 130fc | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:30:44.006516331Z 63 PC: 1311e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:44.009460511Z 66 PC: 13133 | Move file pointer
2018-12-17T22:30:44.01290598Z 64 PC: 13146 | Write file or device (Write 926 bytes on handle 5)
2018-12-17T22:30:44.354341065Z 66 PC: 1315c | Move file pointer
2018-12-17T22:30:44.356586531Z 64 PC: 13167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:44.361205215Z 62 PC: 1316b | Close file
2018-12-17T22:30:44.370637817Z 79 PC: 12fe6 | Find next file
2018-12-17T22:30:44.374912753Z 26 PC: 12ff6 | Set disk transfer address
2018-12-17T22:30:44.37749334Z 37 PC: 12ffd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:44.379061305Z 14 PC: 12f89 | Set default drive (Drive = 'A')