Sample viewer

vx.netlux.org/Virus.DOS.Doser.185

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:42.81055885Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.812848514Z 17 PC: 12a70 | Find first file
2018-12-17T22:35:42.819412685Z 15 PC: 12a7c | Open file (Filename = 'SLEEP COM dLLL[PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:42.826776395Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.828158407Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:42.837617748Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.839083817Z 40 PC: 12abd | Random block write
2018-12-17T22:35:42.855638194Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.860843146Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:42.869619606Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.87104544Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:42.88070175Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:42.883320942Z 15 PC: 12a7c | Open file (Filename = 'PRINT COM "M"M PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:42.890233536Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.891549534Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:42.928478232Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.930043698Z 40 PC: 12abd | Random block write
2018-12-17T22:35:42.936292929Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.938282069Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:42.943558234Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.945060812Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:42.954297666Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:42.959068132Z 15 PC: 12a7c | Open file (Filename = 'HELLO COM dLLL \PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:42.966437413Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.969914574Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:42.977917083Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.979543353Z 40 PC: 12abd | Random block write
2018-12-17T22:35:42.985978161Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.987624318Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:42.993372038Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:42.996019613Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:43.005042255Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:43.008084781Z 15 PC: 12a7c | Open file (Filename = 'PHANG COM rLLrL PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:43.015573145Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.017742002Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:43.025895083Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.027252479Z 40 PC: 12abd | Random block write
2018-12-17T22:35:43.033008264Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.034532172Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:43.041196019Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.043385977Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:43.051771623Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:43.054758696Z 15 PC: 12a7c | Open file (Filename = 'PRINTA~1COM MMPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:43.063710805Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.065561997Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:43.073837457Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.075993951Z 40 PC: 12abd | Random block write
2018-12-17T22:35:43.081375204Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.083473048Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:43.089723981Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.09132278Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:43.099746859Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:43.102741134Z 15 PC: 12a7c | Open file (Filename = 'MANDEL COM (M(MPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:43.110988111Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.112578484Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:43.120474492Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.122820021Z 40 PC: 12abd | Random block write
2018-12-17T22:35:43.133123856Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.13444868Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:43.142865075Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.145138088Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:43.15419316Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:43.157545327Z 15 PC: 12a7c | Open file (Filename = 'PAH COM MPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:43.165144188Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.167134912Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:43.175961977Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.177577186Z 40 PC: 12abd | Random block write
2018-12-17T22:35:43.182879831Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.184396185Z 40 PC: 12ad8 | Random block write
2018-12-17T22:35:43.190500693Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.192038828Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:43.20055534Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:43.204281458Z 15 PC: 12a7c | Open file (Filename = 'TEST COM aMaMPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:35:43.212065717Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.214398432Z 39 PC: 12a9e | Random block read
2018-12-17T22:35:43.219195409Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:35:43.221006756Z 16 PC: 12ae0 | Close file
2018-12-17T22:35:43.223854296Z 18 PC: 12a70 | Find next file
2018-12-17T22:35:43.227613547Z 26 PC: 12aef | Set disk transfer address