Sample viewer

vx.netlux.org/Virus.DOS.Alho.676

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:19.486600064Z 48 PC: 141d4 | Get DOS version
2018-12-17T22:47:19.488992924Z 26 PC: 14205 | Set disk transfer address
2018-12-17T22:47:19.490756511Z 78 PC: 1420e | Find first file
2018-12-17T22:47:19.497627227Z 61 PC: 143cb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:47:19.505495064Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.50742158Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.514647992Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.516136837Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.523277946Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.524955103Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.528059733Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.530258447Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.54578322Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.55510963Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.558408186Z 61 PC: 143cb | Open file (Filename = 'PRINT.COM')
2018-12-17T22:47:19.566034162Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.567764609Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.574869324Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.576636202Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.579382176Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.580873447Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.585224579Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.587005566Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.595589072Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.605246065Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.616096647Z 61 PC: 143cb | Open file (Filename = 'HELLO.COM')
2018-12-17T22:47:19.623534056Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.625973236Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.633472149Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.635045696Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.638674654Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.64057924Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.64400584Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.646623526Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.656002384Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.665236421Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.66911102Z 61 PC: 143cb | Open file (Filename = 'PHANG.COM')
2018-12-17T22:47:19.676392051Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.677846218Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.68508928Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.686969825Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.689596905Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.691065343Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.702654962Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.704589502Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.71362892Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.722934661Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.724926087Z 61 PC: 143cb | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:47:19.729132054Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.730751026Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.735223461Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.736364266Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.738956091Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.740294905Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.742298077Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.743931624Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.749692119Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.758798233Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.761670248Z 61 PC: 143cb | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:47:19.768960596Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.770473581Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.777446656Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.77939084Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.781808856Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.783124455Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.786416933Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.787957732Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.797527593Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.808378286Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.811474536Z 61 PC: 143cb | Open file (Filename = 'PAH.COM')
2018-12-17T22:47:19.819078521Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.821655367Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.829427291Z 66 PC: 14409 | Move file pointer
2018-12-17T22:47:19.831642172Z 63 PC: 14415 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:19.837352771Z 66 PC: 1441e | Move file pointer
2018-12-17T22:47:19.839085373Z 64 PC: 1442a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:47:19.842582142Z 66 PC: 14433 | Move file pointer
2018-12-17T22:47:19.845158702Z 64 PC: 1443f | Write file or device (Write 676 bytes on handle 5)
2018-12-17T22:47:19.854969993Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.863774546Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.868044027Z 61 PC: 143cb | Open file (Filename = 'TEST.COM')
2018-12-17T22:47:19.876669303Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:47:19.878554626Z 63 PC: 143e4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:19.88255315Z 62 PC: 143f6 | Close file
2018-12-17T22:47:19.88480296Z 79 PC: 14218 | Find next file
2018-12-17T22:47:19.887905002Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/k...). Size=00001770h/0000006000d bytes. ')
2018-12-17T22:47:19.894533662Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:47:19.896871434Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:47:19.904500148Z 93 PC: 12afe | File sharing functions
2018-12-17T22:47:19.906928716Z 9 PC: 12a86 | Display string (String= 'Size change=02A4h/00676d. ')
2018-12-17T22:47:19.912374193Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')