Sample viewer

vx.netlux.org/Virus.DOS.Morgoth.189

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:32.644079861Z 26 PC: 12abb | Set disk transfer address
2018-12-17T22:48:32.646014094Z 78 PC: 12ac3 | Find first file
2018-12-17T22:48:32.652947894Z 61 PC: 12ace | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:32.660190878Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.668192063Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.671416688Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.698562303Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.70010679Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.705944678Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.711405733Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.71336251Z 61 PC: 12ace | Open file (Filename = 'PRINT.COM')
2018-12-17T22:48:32.718529008Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.723756487Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.725768079Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.728009669Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.737441571Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.740435808Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.749008777Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.753635837Z 61 PC: 12ace | Open file (Filename = 'HELLO.COM')
2018-12-17T22:48:32.761566039Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.76997672Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.778367815Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.781943135Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.783913005Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.788001316Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.796922755Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.799933746Z 61 PC: 12ace | Open file (Filename = 'PHANG.COM')
2018-12-17T22:48:32.80828814Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.815479962Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.817230802Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.820563132Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.822585698Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.825409616Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.834536691Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.838984419Z 61 PC: 12ace | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:48:32.846602086Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.85392844Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.85658708Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.859900725Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.86171961Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.865360326Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.873916009Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.877000115Z 61 PC: 12ace | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:48:32.884584988Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.891828543Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.893694806Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.90307602Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.904887183Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.912282986Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.923327277Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.926522085Z 61 PC: 12ace | Open file (Filename = 'PAH.COM')
2018-12-17T22:48:32.934793563Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.942153476Z 66 PC: 12aee | Move file pointer
2018-12-17T22:48:32.944722012Z 64 PC: 12bce | Write file or device (Write 301 bytes on handle 5)
2018-12-17T22:48:32.947919595Z 66 PC: 12b10 | Move file pointer
2018-12-17T22:48:32.949663055Z 64 PC: 12b1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:32.953414197Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.962421124Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.965663401Z 61 PC: 12ace | Open file (Filename = 'TEST.COM')
2018-12-17T22:48:32.974218126Z 63 PC: 12ada | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:32.977361467Z 62 PC: 12b1f | Close file
2018-12-17T22:48:32.97958695Z 79 PC: 12ac3 | Find next file
2018-12-17T22:48:32.982974658Z 26 PC: 12b2a | Set disk transfer address
2018-12-17T22:48:32.984235326Z 42 PC: 12b2e | Get date 0x12b2e: cmp dh, byte ptr ds:[bp + 0x213]
0x12b33: je 0x12b40
0x12b35: cmp byte ptr ds:[bp + 0x213], 0xd
0x12b3b: jne 0x12b9d
0x12b3d: nop
0x12b3e: nop
0x12b3f: nop
0x12b40: cmp dl, byte ptr ds:[bp + 0x212]
0x12b45: je 0x12b52
0x12b47: cmp byte ptr ds:[bp + 0x212], 0x20
0x12b4d: jne 0x12b9d
0x12b4f: nop
0x12b50: nop
0x12b51: nop
0x12b52: push cx
0x12b53: push bp
0x12b54: push ax
0x12b55: push dx
0x12b56: mov ax, 0xd
0x12b59: int 0x21
2018-12-17T22:48:32.986900629Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00000064h/0000000100d bytes. ')
2018-12-17T22:48:32.992257796Z 76 PC: 12a86 | Terminate with return code (Return code = '36')