Sample viewer

vx.netlux.org/Virus.DOS.I13.Kraken.1223

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:35.809484508Z 48 PC: 12e35 | Get DOS version
2018-12-17T22:50:35.812304609Z 53 PC: 12e42 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:35.814193152Z 74 PC: 12ea1 | Reallocate memory
2018-12-17T22:50:35.81609384Z 72 PC: 12ea8 | Allocate memory
2018-12-17T22:50:35.81825218Z 37 PC: 12ecd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:35.821107299Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=000003E8h/0000001000d bytes. ')
2018-12-17T22:50:35.826079859Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T22:50:35.829617435Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:50:35.831866837Z 72 PC: 12174 | Allocate memory
2018-12-17T22:50:35.833871064Z 72 PC: 1218d | Allocate memory
2018-12-17T22:50:35.836320003Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:50:35.838392885Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:35.839849054Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.8413121Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.843767806Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.846456705Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.847765712Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.849864911Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.852170863Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.853893403Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.855026658Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.857496259Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.859032007Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.860875636Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.863218115Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.865659709Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.867380294Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.870069251Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.871607172Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.873591436Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.875945257Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.877935289Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.87931625Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.881488585Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.884789924Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.887183655Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.889110389Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.891917993Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.893428175Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.895334539Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.897683436Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.899837703Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.901596934Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.904407245Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.905895636Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.907902866Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.909910312Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.91181527Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.913152899Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.915701159Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.917042282Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.919006083Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.921292391Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.923112826Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.924506665Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.926104413Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.927805119Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.929669173Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.940979446Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.944008699Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.945337177Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.947262312Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.949713304Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.951843313Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.953577645Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.956232978Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.957720039Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.959779703Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.961971652Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.964321131Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.966152049Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.968736136Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:35.971020254Z 62 PC: 122ab | Close file
2018-12-17T22:50:35.97503797Z 99 PC: 9a0f7 | Get DBCS lead byte table pointer
2018-12-17T22:50:35.976728546Z 56 PC: 94919 | Get or set country info
2018-12-17T22:50:35.980018669Z 64 PC: 9a368 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:50:35.985218838Z 25 PC: 94982 | Get default drive
2018-12-17T22:50:35.986999376Z 71 PC: 96bfd | Get current directory
2018-12-17T22:50:36.002308172Z 64 PC: 9a368 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:50:36.007379965Z 2 PC: 96bd2 | Character output (Char = '3e')
2018-12-17T22:50:36.009805688Z 93 PC: 94a40 | File sharing functions
2018-12-17T22:50:36.012295113Z 93 PC: 94a47 | File sharing functions
2018-12-17T22:50:36.014532505Z 10 PC: 94a59 | Buffered keyboard input
2018-12-17T22:50:50.786826551Z 0 PC: 0 | Program terminate
2018-12-17T22:50:52.14170763Z 0 PC: 0 | Program terminate
2018-12-17T22:50:52.244395134Z 64 PC: 9a368 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:50:52.252041755Z 41 PC: 94ace | Parse filename
2018-12-17T22:50:52.254216704Z 41 PC: 94b4f | Parse filename
2018-12-17T22:50:52.256408779Z 41 PC: 94b6c | Parse filename
2018-12-17T22:50:52.260652795Z 26 PC: 98017 | Set disk transfer address
2018-12-17T22:50:52.262460166Z 71 PC: 98213 | Get current directory
2018-12-17T22:50:52.271618719Z 78 PC: 9f8c2 | Find first file
2018-12-17T22:50:52.283499812Z 47 PC: 9f8cd | Get disk transfer address
2018-12-17T22:50:52.28524848Z 71 PC: 9808c | Get current directory
2018-12-17T22:50:52.288783103Z 73 PC: 97729 | Release memory
2018-12-17T22:50:52.292821934Z 53 PC: 9fa7a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.294948029Z 37 PC: 9fa8e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.298833974Z 61 PC: 9fac1 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:50:52.306315465Z 87 PC: 9facd | Get or set file date and time
2018-12-17T22:50:52.308035965Z 63 PC: 9faf1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:50:52.315361238Z 66 PC: 9fbe8 | Move file pointer
2018-12-17T22:50:52.317007748Z 62 PC: 9fb49 | Close file
2018-12-17T22:50:52.320005119Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.321681076Z 75 PC: 11821 | Execute program
2018-12-17T22:50:52.333407575Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:50:52.338167997Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:50:52.341589403Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:50:52.342922622Z 72 PC: 12174 | Allocate memory
2018-12-17T22:50:52.345363061Z 72 PC: 1218d | Allocate memory
2018-12-17T22:50:52.34725451Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:50:52.348556732Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:52.350355654Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.351738335Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.353497242Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.356178715Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.357397026Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.359155134Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.361116459Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.362614065Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.363676073Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.365994069Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.367653997Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.369018741Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.370716845Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.372047492Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.373156249Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.3746014Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.376190458Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.382502382Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.38357274Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.388614916Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.38950159Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.390700854Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.392136022Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.393337286Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.394195752Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.395549485Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.396492339Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.397724342Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.399599837Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.400815546Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.402680929Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.405134929Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.40628261Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.407948946Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.409467956Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.411274398Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.412524593Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.414741512Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.416040914Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.417705602Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.418900085Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.420574192Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.421886411Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.423991874Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.425922927Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.427894139Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.429744402Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.431456649Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.432588896Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.434437343Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.43576215Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.437502337Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.438789258Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.440505456Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.441837373Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.450763063Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.451891092Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.453578932Z 53 PC: 9fb74 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.455119079Z 37 PC: 9fb88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.456819815Z 37 PC: 9fb54 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:52.457995875Z 62 PC: 122ab | Close file
2018-12-17T22:50:52.461381537Z 99 PC: 9a0f7 | Get DBCS lead byte table pointer
2018-12-17T22:50:52.462998308Z 56 PC: 94919 | Get or set country info
2018-12-17T22:50:52.465994849Z 64 PC: 9a368 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:50:52.471645787Z 25 PC: 94982 | Get default drive
2018-12-17T22:50:52.478743176Z 71 PC: 96bfd | Get current directory
2018-12-17T22:50:52.483080048Z 64 PC: 9a368 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:50:52.487226375Z 2 PC: 96bd2 | Character output (Char = '3e')
2018-12-17T22:50:52.489725986Z 93 PC: 94a40 | File sharing functions
2018-12-17T22:50:52.491640545Z 93 PC: 94a47 | File sharing functions
2018-12-17T22:50:52.494338766Z 10 PC: 94a59 | Buffered keyboard input