Sample viewer

vx.netlux.org/Virus.DOS.Doser.194

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:30.814158999Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.8159718Z 17 PC: 12e5c | Find first file
2018-12-17T21:58:30.819825955Z 15 PC: 12e68 | Open file (Filename = 'SLEEP COM dLLL>!CڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:30.82408878Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.825483145Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:30.830725189Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.831682514Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:30.845502447Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.846572161Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:30.854360743Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.855698903Z 16 PC: 12ecc | Close file
2018-12-17T21:58:30.864546754Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:30.866957485Z 15 PC: 12e68 | Open file (Filename = 'PRINT COM "M"M CڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:30.874044031Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.875211198Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:30.883853463Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.885400162Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:30.891887571Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.892834581Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:30.900579253Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.902471134Z 16 PC: 12ecc | Close file
2018-12-17T21:58:30.910629988Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:30.913062122Z 15 PC: 12e68 | Open file (Filename = 'HELLO COM dLLL \CڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:30.921050258Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.923194469Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:30.930730602Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.934983222Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:30.939784116Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.94102699Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:30.947562957Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.948804322Z 16 PC: 12ecc | Close file
2018-12-17T21:58:30.957356995Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:30.960655029Z 15 PC: 12e68 | Open file (Filename = 'PHANG COM rLLrL CڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:30.968144618Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.969747674Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:30.989093964Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.990614576Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:30.994576943Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:30.996417338Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:31.001004354Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.002932264Z 16 PC: 12ecc | Close file
2018-12-17T21:58:31.009706292Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:31.02382902Z 15 PC: 12e68 | Open file (Filename = 'PRINTA~1COM MMCڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:31.031497247Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.032952577Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:31.041795105Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.04646936Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:31.051714616Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.053983055Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:31.058212095Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.059886659Z 16 PC: 12ecc | Close file
2018-12-17T21:58:31.067642327Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:31.069843114Z 15 PC: 12e68 | Open file (Filename = 'MANDEL COM (M(MCڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:31.075649779Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.077505885Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:31.084383604Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.0855569Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:31.094200838Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.095735896Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:31.102713714Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.104033975Z 16 PC: 12ecc | Close file
2018-12-17T21:58:31.111666158Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:31.114106372Z 15 PC: 12e68 | Open file (Filename = 'PAH COM MCڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:31.121430689Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.122864326Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:31.130270697Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.131613661Z 40 PC: 12ea9 | Random block write
2018-12-17T21:58:31.137000041Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.137989049Z 40 PC: 12ec4 | Random block write
2018-12-17T21:58:31.14250703Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.144072369Z 16 PC: 12ecc | Close file
2018-12-17T21:58:31.151969609Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:31.154625247Z 15 PC: 12e68 | Open file (Filename = 'TEST COM UMUMCڴE!E!E!>!Y^&&1^n#&>&t&&SV3ɬA<u6!NQ6>o!t+6>o!Oq!>o!Y^I6:!tQ!&E:$uFIo!=!rش>!Y^"?=Au#')
2018-12-17T21:58:31.163379117Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.164746819Z 39 PC: 12e8a | Random block read
2018-12-17T21:58:31.168714277Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.170546852Z 16 PC: 12ecc | Close file
2018-12-17T21:58:31.172752213Z 18 PC: 12e5c | Find next file
2018-12-17T21:58:31.174336414Z 26 PC: 12edb | Set disk transfer address
2018-12-17T21:58:31.175568575Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=000003E8h/0000001000d bytes. ')
2018-12-17T21:58:31.177921384Z 76 PC: 12a86 | Terminate with return code (Return code = '36')