Sample viewer

vx.netlux.org/Virus.DOS.Ugadaj.739

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:22.81105229Z 240 PC: 13eb0 | UNKNOWN!
2018-12-17T22:35:22.812747879Z 74 PC: 13eb0 | Reallocate memory
2018-12-17T22:35:22.814366291Z 82 PC: 13eb0 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:35:22.815741439Z 80 PC: 13eb0 | Set current PSP
2018-12-17T22:35:22.816942716Z 72 PC: 13eb0 | Allocate memory
2018-12-17T22:35:22.819179296Z 80 PC: 13eb0 | Set current PSP
2018-12-17T22:35:22.820401714Z 53 PC: 13eb0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:22.821932784Z 37 PC: 13eb0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:22.824141373Z 53 PC: 9f950 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:22.82550197Z 37 PC: 9f950 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:22.826799477Z 47 PC: 9f950 | Get disk transfer address
2018-12-17T22:35:22.828745912Z 26 PC: 9f950 | Set disk transfer address
2018-12-17T22:35:22.830131668Z 78 PC: 9f950 | Find first file
2018-12-17T22:35:22.836389713Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:22.854430852Z 61 PC: 9f950 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:35:22.861113001Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.86269604Z 63 PC: 9f950 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:35:22.871806596Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.873290721Z 63 PC: 9f950 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:35:22.875788604Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.87812296Z 64 PC: 9f950 | Write file or device (Write 739 bytes on handle 5)
2018-12-17T22:35:22.88731824Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.888643596Z 64 PC: 9f950 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:35:22.894650521Z 62 PC: 9f950 | Close file
2018-12-17T22:35:22.903446312Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:22.91325416Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:22.915891206Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:22.919542189Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:22.93003073Z 61 PC: 9f950 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:35:22.936684015Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.939338294Z 63 PC: 9f950 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:35:22.946623967Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.948286331Z 63 PC: 9f950 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:35:22.953583848Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.955262152Z 64 PC: 9f950 | Write file or device (Write 739 bytes on handle 5)
2018-12-17T22:35:22.963512217Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:22.965582369Z 64 PC: 9f950 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:35:22.973253314Z 62 PC: 9f950 | Close file
2018-12-17T22:35:22.981268886Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:22.988812072Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:22.991144529Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:22.993707315Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:22.995697709Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:23.003515278Z 61 PC: 9f950 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:35:23.008024254Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:23.009138757Z 63 PC: 9f950 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:35:23.013838199Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:23.014894043Z 63 PC: 9f950 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:35:23.017012194Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:23.018477609Z 64 PC: 9f950 | Write file or device (Write 739 bytes on handle 5)
2018-12-17T22:35:23.024272593Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:23.02542951Z 64 PC: 9f950 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:35:23.030567918Z 62 PC: 9f950 | Close file
2018-12-17T22:35:23.036443678Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:23.044824198Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:23.047928504Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:23.049828124Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:23.055985882Z 61 PC: 9f950 | Open file (Filename = 'TEST.COM')
2018-12-17T22:35:23.064492611Z 66 PC: 9f950 | Move file pointer
2018-12-17T22:35:23.06616771Z 63 PC: 9f950 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:35:23.07300382Z 67 PC: 9f950 | Get or set file attributes
2018-12-17T22:35:23.084370076Z 79 PC: 9f950 | Find next file
2018-12-17T22:35:23.086749362Z 26 PC: 9f950 | Set disk transfer address
2018-12-17T22:35:23.087845291Z 37 PC: 9f950 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:23.09028374Z 9 PC: 12a85 | Display string (String= ' COM goat 1400H bytes long ')
2018-12-17T22:35:23.095595129Z 0 PC: 12a89 | Program terminate