Sample viewer

vx.netlux.org/Virus.DOS.Andrey.932

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:36.0114385Z 105 PC: 16de4 | Get or set media id
2018-12-17T22:43:36.01360949Z 53 PC: 16e23 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:36.014758736Z 37 PC: 16e33 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:36.015837881Z 53 PC: 16e38 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:43:36.017942861Z 37 PC: 16e48 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:43:36.020034702Z 53 PC: 163f8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:36.02134698Z 37 PC: 1647c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:36.022559292Z 26 PC: 16500 | Set disk transfer address
2018-12-17T22:43:36.024350731Z 78 PC: 1654e | Find first file
2018-12-17T22:43:36.030327441Z 61 PC: 16592 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:36.036862236Z 63 PC: 165ec | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:43:36.044237185Z 62 PC: 16688 | Close file
2018-12-17T22:43:36.046046901Z 67 PC: 166b0 | Get or set file attributes
2018-12-17T22:43:36.063141665Z 61 PC: 166e6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:36.072176595Z 66 PC: 16c21 | Move file pointer
2018-12-17T22:43:36.07356551Z 64 PC: 16c78 | Write file or device (Write 2028 bytes on handle 5)
2018-12-17T22:43:36.082541907Z 66 PC: 16c91 | Move file pointer
2018-12-17T22:43:36.084614935Z 64 PC: 16cc8 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:43:36.092736274Z 87 PC: 16844 | Get or set file date and time
2018-12-17T22:43:36.09457352Z 62 PC: 1684d | Close file
2018-12-17T22:43:36.096628176Z 67 PC: 1687f | Get or set file attributes
2018-12-17T22:43:36.107818735Z 26 PC: 168d2 | Set disk transfer address
2018-12-17T22:43:36.108944208Z 37 PC: 16909 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:36.110182505Z 26 PC: 16399 | Set disk transfer address
2018-12-17T22:43:36.112044517Z 78 PC: 16339 | Find first file
2018-12-17T22:43:36.118245407Z 61 PC: 16344 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:36.124937955Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.128503519Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.129854847Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.132421626Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.135085788Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.14286984Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.151362038Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.154668672Z 61 PC: 16344 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:43:36.161011564Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.167249175Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.169337732Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.172975138Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.174475162Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.178082538Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.185691661Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.188185673Z 61 PC: 16344 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:43:36.195233667Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.205187981Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.206517841Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.209898509Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.211245911Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.213800057Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.2222247Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.2247509Z 61 PC: 16344 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:43:36.231102998Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.237823707Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.23918413Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.241732715Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.244164757Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.246711943Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.254641662Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.25767956Z 61 PC: 16344 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:43:36.264008011Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.270170188Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.27223001Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.274781359Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.276099215Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.29423543Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.302421092Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.305462591Z 61 PC: 16344 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:43:36.312820923Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.319416048Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.321140293Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.324549838Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.326282836Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.334552612Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.343092749Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.345652877Z 61 PC: 16344 | Open file (Filename = 'PAH.COM')
2018-12-17T22:43:36.362076941Z 63 PC: 16350 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:36.369303356Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.370547612Z 64 PC: 1637a | Write file or device (Write 3 bytes on handle 6)
2018-12-17T22:43:36.372952328Z 66 PC: 163a1 | Move file pointer
2018-12-17T22:43:36.375030869Z 64 PC: 1638a | Write file or device (Write 150 bytes on handle 6)
2018-12-17T22:43:36.377585087Z 62 PC: 1638e | Close file
2018-12-17T22:43:36.384976607Z 79 PC: 16339 | Find next file
2018-12-17T22:43:36.388753812Z 26 PC: 16399 | Set disk transfer address
2018-12-17T22:43:36.390147771Z 25 PC: 1515d | Get default drive
2018-12-17T22:43:36.391295516Z 48 PC: 15162 | Get DOS version
2018-12-17T22:43:36.393246223Z 37 PC: 15186 | Set interrupt vector (Interrupt = '200' AKA 'UNKNOWN!')
2018-12-17T22:43:36.394408345Z 84 PC: 1518a | Get verify flag
2018-12-17T22:43:36.398285262Z 47 PC: 15192 | Get disk transfer address
2018-12-17T22:43:36.405006583Z 52 PC: 15254 | Get InDOS flag pointer
2018-12-17T22:43:36.408924357Z 53 PC: 152a5 | Get interrupt vector (Interrupt = '10' AKA 'Buffered keyboard input')
2018-12-17T22:43:36.410129519Z 82 PC: 152e5 | Get DOS internal pointers (SYSVARS)