Sample viewer

vx.netlux.org/Virus.DOS.Goma.563

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:46.5047027Z 26 PC: 14086 | Set disk transfer address
2018-12-17T22:43:46.506916782Z 250 PC: 1429f | UNKNOWN!
2018-12-17T22:43:46.509239587Z 42 PC: 1429f | Get date 0x1429f: ret
0x142a0: int 0x13
0x142a2: ret
0x142a3: jmp 0x158d9
0x142a6: add di, di
0x142a9: jne 0x142cb
0x142ab: mov byte ptr [0x363], 1
0x142b0: push ds
0x142b1: mov ds, word ptr [0x31a]
0x142b5: cmp byte ptr [2], 0
0x142ba: pop ds
0x142bb: je 0x142c8
0x142bd: call 0x146a1
0x142c0: mov byte ptr es:[0xa166], al
0x142c4: call 0x168b1
0x142c7: ret
0x142c8: call 0x2420c
0x142cb: mov di, 0xa166
0x142ce: mov ax, ds
0x142d0: mov ds, word ptr [0x31a]
2018-12-17T22:43:46.511699322Z 78 PC: 140d6 | Find first file
2018-12-17T22:43:46.51875725Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:46.524498954Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.542402528Z 61 PC: 1419a | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:46.550098915Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:46.552346441Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:46.559124696Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.560929184Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.564149246Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:46.572407713Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.573787926Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.582507538Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:46.583988979Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.594373641Z 62 PC: 141ff | Close file
2018-12-17T22:43:46.602063663Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:46.604647403Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:46.610147515Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.627832885Z 61 PC: 1419a | Open file (Filename = 'PRINT.COM')
2018-12-17T22:43:46.638877943Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:46.64021917Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:46.64727129Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.648577555Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.651794087Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:46.660040425Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.661534703Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.667745883Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:46.669266992Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.683920228Z 62 PC: 141ff | Close file
2018-12-17T22:43:46.69351405Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:46.696143352Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:46.70182549Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.71219807Z 61 PC: 1419a | Open file (Filename = 'HELLO.COM')
2018-12-17T22:43:46.718842055Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:46.721068203Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:46.727783341Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.729560784Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.733678156Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:46.741668579Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.743071551Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.750722987Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:46.752349367Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.763025696Z 62 PC: 141ff | Close file
2018-12-17T22:43:46.770623939Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:46.773183492Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:46.779696211Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.789771987Z 61 PC: 1419a | Open file (Filename = 'PHANG.COM')
2018-12-17T22:43:46.796124002Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:46.797483201Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:46.80436021Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.805746868Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.808271304Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:46.81704657Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.818452077Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.824686335Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:46.827148347Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.83750807Z 62 PC: 141ff | Close file
2018-12-17T22:43:46.844266672Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:46.848002465Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:46.854302544Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.863822423Z 61 PC: 1419a | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:43:46.870735799Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:46.873363582Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:46.879703971Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.881080378Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.884794984Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:46.892424281Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.893761207Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.901251122Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:46.902721972Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.913797174Z 62 PC: 141ff | Close file
2018-12-17T22:43:46.920993986Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:46.923492231Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:46.928901422Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.939120707Z 61 PC: 1419a | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:43:46.945519896Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:46.946786681Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:46.953422214Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.954759882Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.957308658Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:46.966393188Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:46.967978594Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:46.974559929Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:46.977066723Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:46.991799081Z 62 PC: 141ff | Close file
2018-12-17T22:43:46.998509724Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:47.001823307Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:47.007407177Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:47.017102749Z 61 PC: 1419a | Open file (Filename = 'PAH.COM')
2018-12-17T22:43:47.024644674Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:47.02600168Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:47.032308123Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:47.034370378Z 64 PC: 141de | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:47.037085617Z 64 PC: 14231 | Write file or device (Write 560 bytes on handle 5)
2018-12-17T22:43:47.044923293Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:47.04695401Z 64 PC: 141ec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:47.053653812Z 87 PC: 141f5 | Get or set file date and time
2018-12-17T22:43:47.055066887Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:47.066013735Z 62 PC: 141ff | Close file
2018-12-17T22:43:47.072781037Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:47.075343522Z 67 PC: 1418d | Get or set file attributes
2018-12-17T22:43:47.081921787Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:47.091979479Z 61 PC: 1419a | Open file (Filename = 'TEST.COM')
2018-12-17T22:43:47.103069277Z 87 PC: 141a2 | Get or set file date and time
2018-12-17T22:43:47.104822447Z 63 PC: 141af | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:43:47.112443851Z 66 PC: 1423d | Move file pointer
2018-12-17T22:43:47.114793167Z 67 PC: 14224 | Get or set file attributes
2018-12-17T22:43:47.12470757Z 62 PC: 141ff | Close file
2018-12-17T22:43:47.126867642Z 79 PC: 140e6 | Find next file
2018-12-17T22:43:47.12950559Z 26 PC: 14099 | Set disk transfer address
2018-12-17T22:43:47.130868348Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:43:47.136408837Z 0 PC: 12a89 | Program terminate