Sample viewer

vx.netlux.org/Virus.DOS.Xor.289

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:27.854472518Z 71 PC: 17874 | Get current directory
2018-12-17T22:34:27.857123902Z 26 PC: 1787c | Set disk transfer address
2018-12-17T22:34:27.858125362Z 78 PC: 178c2 | Find first file
2018-12-17T22:34:27.862344513Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:27.866655501Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:27.881615639Z 61 PC: 178ec | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:34:27.88894022Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:27.890889631Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:27.897966392Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:27.899573365Z 64 PC: 17945 | Write file or device (Write 289 bytes on handle 5)
2018-12-17T22:34:27.90827333Z 66 PC: 1794e | Move file pointer
2018-12-17T22:34:27.910129104Z 64 PC: 17959 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:34:27.91784246Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:27.920036783Z 62 PC: 17968 | Close file
2018-12-17T22:34:27.932378902Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:27.943643828Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:27.946528333Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:27.9530505Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:27.963760861Z 61 PC: 178ec | Open file (Filename = 'PRINT.COM')
2018-12-17T22:34:27.970881651Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:27.972950955Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:27.980057664Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:27.981614832Z 64 PC: 17945 | Write file or device (Write 289 bytes on handle 5)
2018-12-17T22:34:27.996355343Z 66 PC: 1794e | Move file pointer
2018-12-17T22:34:27.998046421Z 64 PC: 17959 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:34:28.000932891Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.003176528Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.011956325Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.023425511Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.027882065Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:28.034287472Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:28.04551674Z 61 PC: 178ec | Open file (Filename = 'HELLO.COM')
2018-12-17T22:34:28.052898382Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:28.054594489Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:28.061580151Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:28.063092015Z 64 PC: 17945 | Write file or device (Write 289 bytes on handle 5)
2018-12-17T22:34:28.067710602Z 66 PC: 1794e | Move file pointer
2018-12-17T22:34:28.070492989Z 64 PC: 17959 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:34:28.073385423Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.075856416Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.085578251Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.097501394Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.101961081Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:28.108242265Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:28.118989706Z 61 PC: 178ec | Open file (Filename = 'PHANG.COM')
2018-12-17T22:34:28.127487898Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:28.128867934Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:28.133181157Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:28.135168969Z 64 PC: 17945 | Write file or device (Write 289 bytes on handle 5)
2018-12-17T22:34:28.137606502Z 66 PC: 1794e | Move file pointer
2018-12-17T22:34:28.138895737Z 64 PC: 17959 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:34:28.141832046Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.143724893Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.152005326Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.163363048Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.166471146Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:28.172728245Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:28.183497024Z 61 PC: 178ec | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:34:28.191428546Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:28.193253081Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:28.20115427Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:28.203332177Z 64 PC: 17945 | Write file or device (Write 289 bytes on handle 5)
2018-12-17T22:34:28.206327494Z 66 PC: 1794e | Move file pointer
2018-12-17T22:34:28.207835204Z 64 PC: 17959 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:34:28.21120174Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.212772781Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.220816286Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.233425751Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.236278182Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:28.243394463Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:28.255236724Z 61 PC: 178ec | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:34:28.263128593Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:28.265702536Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:28.273469537Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:28.275866191Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.277623488Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.286556164Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.297492136Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.300357525Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:28.30727385Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:28.318018972Z 61 PC: 178ec | Open file (Filename = 'PAH.COM')
2018-12-17T22:34:28.331641872Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:28.334510446Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:28.341597741Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:28.343127029Z 64 PC: 17945 | Write file or device (Write 289 bytes on handle 5)
2018-12-17T22:34:28.346254594Z 66 PC: 1794e | Move file pointer
2018-12-17T22:34:28.34794396Z 64 PC: 17959 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:34:28.351848128Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.353631359Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.362069099Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.372873231Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.375686368Z 67 PC: 178d7 | Get or set file attributes
2018-12-17T22:34:28.382986552Z 67 PC: 178e3 | Get or set file attributes
2018-12-17T22:34:28.39367985Z 61 PC: 178ec | Open file (Filename = 'TEST.COM')
2018-12-17T22:34:28.401904893Z 87 PC: 178f2 | Get or set file date and time
2018-12-17T22:34:28.404051401Z 63 PC: 178ff | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:34:28.411942699Z 66 PC: 17908 | Move file pointer
2018-12-17T22:34:28.413405075Z 87 PC: 17964 | Get or set file date and time
2018-12-17T22:34:28.415538761Z 62 PC: 17968 | Close file
2018-12-17T22:34:28.423441491Z 67 PC: 1796d | Get or set file attributes
2018-12-17T22:34:28.4343006Z 79 PC: 178c2 | Find next file
2018-12-17T22:34:28.437642292Z 59 PC: 178b0 | Change current directory
2018-12-17T22:34:28.444288536Z 26 PC: 178b7 | Set disk transfer address
2018-12-17T22:34:28.445810106Z 9 PC: 17788 | Display string (String= 'Goat file (COM/b...). Size=00004E20h/0000020000d bytes. ')
2018-12-17T22:34:28.452721514Z 48 PC: 17791 | Get DOS version
2018-12-17T22:34:28.454336871Z 61 PC: 1785e | Open file (Filename = '')
2018-12-17T22:34:28.462676821Z 93 PC: 17800 | File sharing functions
2018-12-17T22:34:28.465355323Z 9 PC: 17788 | Display string (String= 'Size change=0121h/00289d. ')
2018-12-17T22:34:28.470392061Z 76 PC: 177e5 | Terminate with return code (Return code = '1')