Sample viewer

vx.netlux.org/Virus.DOS.Sobakin.9592

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:44.316097428Z 25 PC: 13e4b | Get default drive
2018-12-17T22:54:44.330633058Z 82 PC: 13ee0 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:54:44.33486413Z 48 PC: 13f21 | Get DOS version
2018-12-17T22:54:44.336723859Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.337968447Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.340138861Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.341418705Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:54:44.347626312Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.349798091Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.351998887Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.353440295Z 0 PC: 12a89 | Program terminate
2018-12-17T22:54:44.357351126Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.358984971Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.360745216Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.362891909Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:54:44.364327766Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.365643716Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.368110471Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.369500308Z 72 PC: 12174 | Allocate memory
2018-12-17T22:54:44.371454989Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.373999345Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.375648746Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.377365791Z 72 PC: 1218d | Allocate memory
2018-12-17T22:54:44.380386676Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.38275557Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.384738194Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.386547148Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:54:44.389444084Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.391321723Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.393111208Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.395849304Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:44.397481811Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.399083151Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.402037316Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.403647384Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.405441551Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.407691995Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.412794439Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.414272717Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.417217372Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.419052882Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.421425411Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.422928054Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.424902269Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.42619293Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.427973244Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.429940255Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.431715409Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.433117357Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.438723212Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.440427188Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.442529364Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.447707962Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.450015954Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.451424344Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.454141158Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.455551798Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.457491368Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.45960583Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.461381486Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.462724681Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.464635752Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.466412968Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.468872713Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.470470865Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.473327197Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.475189279Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.478172895Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.480717941Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.483196058Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.485037119Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.488420732Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.490261566Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.492466576Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.494560291Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.496788709Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.498561282Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.501960296Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.503519396Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.505562412Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.507388776Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.50975917Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.511406691Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.513674607Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.515853649Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.518927845Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.520592565Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.522380831Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.52341738Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.524978153Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.526649859Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.527954603Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.528916897Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.531483201Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.532514593Z 62 PC: 122ab | Close file
2018-12-17T22:54:44.534368658Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.536170827Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.538419464Z 67 PC: 9af84 | Get or set file attributes
2018-12-17T22:54:44.545053508Z 67 PC: 9af84 | Get or set file attributes
2018-12-17T22:54:44.887704048Z 61 PC: 9af84 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:54:44.895334036Z 87 PC: 9af84 | Get or set file date and time
2018-12-17T22:54:44.897108145Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.899475734Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.90107966Z 63 PC: 9af84 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:54:44.904327009Z 87 PC: 9af84 | Get or set file date and time
2018-12-17T22:54:44.905980741Z 62 PC: 9af84 | Close file
2018-12-17T22:54:44.91291673Z 67 PC: 9af84 | Get or set file attributes
2018-12-17T22:54:44.917751514Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.918911772Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:54:44.927499263Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.928822528Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.930254744Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.93268359Z 66 PC: 12372 | Move file pointer
2018-12-17T22:54:44.934387302Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.935808225Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.937888635Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.939345815Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T22:54:44.954921316Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.957574332Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:44.959967848Z 42 PC: 9af84 | Get date 0x9af84: ret
0x9af85: lcall 0x19:0x40f8
0x9af8a: ret
0x9af8b: pushf
0x9af8c: cmp ah, 0x30
0x9af8f: jne 0x9afad
0x9af91: cmp si, 0xdead
0x9af95: jne 0x9afad
0x9af97: cmp di, 0x7ce
0x9af9b: jne 0x9afad
0x9af9d: xor di, 0xc710
0x9afa1: push di
0x9afa2: sub di, si
0x9afa4: add di, 0x436
0x9afa8: not di
0x9afaa: pop si
0x9afab: popf
0x9afac: iret
0x9afad: call 0x9b3bb
0x9afb0: push cs
2018-12-17T22:54:44.962433121Z 87 PC: 9af84 | Get or set file date and time
2018-12-17T22:54:44.964194161Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.96629429Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.967632875Z 63 PC: 9af84 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:54:44.96973702Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.971381494Z 63 PC: 9af84 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:54:44.973396233Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.974641413Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.976358306Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:44.97749134Z 64 PC: 9af84 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:44.979395668Z 66 PC: 9af84 | Move file pointer
2018-12-17T22:54:45.006639073Z 64 PC: 9af84 | Write file or device (Write 9736 bytes on handle 5)
2018-12-17T22:54:45.024194511Z 64 PC: 9af84 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:54:45.027502196Z 87 PC: 9af84 | Get or set file date and time
2018-12-17T22:54:45.029795142Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.03168178Z 62 PC: 1238a | Close file
2018-12-17T22:54:45.043104655Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.045530765Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.04727031Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.048934377Z 99 PC: 95807 | Get DBCS lead byte table pointer
2018-12-17T22:54:45.051896202Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.053356649Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.054951773Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.058152013Z 56 PC: 90029 | Get or set country info
2018-12-17T22:54:45.061013959Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.063124553Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.065374973Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.067165398Z 64 PC: 95a78 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:54:45.073699182Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.077530277Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.080068817Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.08168792Z 25 PC: 90092 | Get default drive
2018-12-17T22:54:45.084764824Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.086798685Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.088792656Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.091017339Z 71 PC: 9230d | Get current directory
2018-12-17T22:54:45.096243765Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.098157107Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.101586822Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.10349224Z 64 PC: 95a78 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:54:45.107768561Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.111525228Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.11375489Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.115686641Z 2 PC: 922e2 | Character output (Char = '3e')
2018-12-17T22:54:45.118728299Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.121163146Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.123198383Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.124893814Z 93 PC: 90150 | File sharing functions
2018-12-17T22:54:45.128432976Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.130143493Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.132040565Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.135661794Z 93 PC: 90157 | File sharing functions
2018-12-17T22:54:45.13780869Z 53 PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.139248704Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.141837103Z 37 PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.144095678Z 10 PC: 90169 | Buffered keyboard input