Sample viewer

vx.netlux.org/Virus.DOS.Edit.684

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:39.198583336Z 61 PC: 12a5c | Open file (Filename = '')
2018-12-17T21:57:39.201509969Z 61 PC: 9f88d | Open file (Filename = '1FF')
2018-12-17T21:57:39.21332526Z 26 PC: 12ac6 | Set disk transfer address
2018-12-17T21:57:39.21552179Z 78 PC: 9f843 | Find first file
2018-12-17T21:57:39.238934881Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.240539669Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.247304575Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.253953908Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.256120683Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.259152539Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.261864319Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.273252811Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.277601691Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.287123947Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.288959442Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.295740694Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.303333743Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.306688747Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.309485786Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.31094007Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.318338956Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.324549425Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.326340582Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.330313306Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.331813887Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.338660154Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.346384565Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.348491456Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.351468685Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.354219134Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.361139483Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.367668058Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.36993997Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.372562651Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.374949632Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.382417309Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.389053037Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.391208251Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.394360046Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.395996634Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.40343162Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.410238525Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.412807402Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.41592892Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.41734352Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.424455118Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.432657218Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.434514751Z 79 PC: 9f843 | Find next file
2018-12-17T21:57:39.438859791Z 47 PC: 9f857 | Get disk transfer address
2018-12-17T21:57:39.440345922Z 61 PC: 9f88d | Open file (Filename = '>!j')
2018-12-17T21:57:39.447216062Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.455118639Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.457289025Z 61 PC: 12af8 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T21:57:39.464889983Z 63 PC: 12b26 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.473026197Z 64 PC: 12b43 | Write file or device (Write 684 bytes on handle 5)
2018-12-17T21:57:39.48663029Z 62 PC: 12b47 | Close file
2018-12-17T21:57:39.495134909Z 13 PC: 12b4b | Disk reset
2018-12-17T21:57:39.497571402Z 74 PC: 12b54 | Reallocate memory
2018-12-17T21:57:39.499134517Z 75 PC: 12b69 | Execute program
2018-12-17T21:57:39.51393701Z 9 PC: 12d65 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T21:57:39.520326232Z 0 PC: 12d69 | Program terminate
2018-12-17T21:57:39.523881195Z 61 PC: 9f88d | Open file (Filename = '')
2018-12-17T21:57:39.530777996Z 63 PC: 9f8d6 | Read file or device (Read 684 bytes on handle 5)
2018-12-17T21:57:39.538872878Z 64 PC: 9f905 | Write file or device (Write 684 bytes on handle 5)
2018-12-17T21:57:39.547395637Z 64 PC: 9f92f | Write file or device (Write 684 bytes on handle 5)
2018-12-17T21:57:39.555056256Z 62 PC: 9f933 | Close file
2018-12-17T21:57:39.563532189Z 77 PC: 12b77 | Get program return code
2018-12-17T21:57:39.564928282Z 76 PC: 12b7b | Terminate with return code (Return code = '0')