Sample viewer

vx.netlux.org/Virus.DOS.Doser.184.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:53.245048783Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.246336913Z 17 PC: 12a6e | Find first file
2018-12-17T22:41:53.25233939Z 15 PC: 12a7a | Open file (Filename = 'SLEEP COM dLLL[PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.258986645Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.260318202Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.268013272Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.269144135Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.284522067Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.2931226Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.301004774Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.302066205Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.31109615Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.313639907Z 15 PC: 12a7a | Open file (Filename = 'PRINT COM "M"M PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.321031717Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.322764404Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.330154365Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.331604722Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.338512453Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.340234758Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.345265535Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.347734344Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.355785075Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.358323546Z 15 PC: 12a7a | Open file (Filename = 'HELLO COM dLLL \PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.365978108Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.367610577Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.376037073Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.383405576Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.390879983Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.392431998Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.400623019Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.401807456Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.409844689Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.413148814Z 15 PC: 12a7a | Open file (Filename = 'PHANG COM rLLrL PSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.420004673Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.421146934Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.429311084Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.430455423Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.435183598Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.436859324Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.441574458Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.442634738Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.450783327Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.454106594Z 15 PC: 12a7a | Open file (Filename = 'PRINTA~1COM MMPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.460947715Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.462227596Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.470327746Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.471618339Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.476800862Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.479003967Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.484087045Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.485502872Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.494365435Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.497434581Z 15 PC: 12a7a | Open file (Filename = 'MANDEL COM (M(MPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.504318699Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.50616491Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.513915802Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.515157839Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.525844945Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.526906259Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.534605345Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.536314166Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.544948824Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.547381216Z 15 PC: 12a7a | Open file (Filename = 'PAH COM MPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.554637405Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.555769527Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.562895394Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.564415565Z 40 PC: 12abb | Random block write
2018-12-17T22:41:53.569084737Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.57122989Z 40 PC: 12ad6 | Random block write
2018-12-17T22:41:53.57669511Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.578316614Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.586370013Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.589144801Z 15 PC: 12a7a | Open file (Filename = 'TEST COM ,M,MPSQRV ; tZ;rZH;>rG l!r?؋33ɸB!r5@?!r u F5 u>!&= u^ZY[XˊȸX!ɀက ٸX!2X! P!0!=tS"[&9t &£!')
2018-12-17T22:41:53.595873813Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.596835291Z 39 PC: 12a9c | Random block read
2018-12-17T22:41:53.600279615Z 26 PC: 12aed | Set disk transfer address
2018-12-17T22:41:53.601539041Z 16 PC: 12ade | Close file
2018-12-17T22:41:53.603751096Z 18 PC: 12a6e | Find next file
2018-12-17T22:41:53.606647761Z 26 PC: 12aed | Set disk transfer address