Sample viewer

vx.netlux.org/Virus.DOS.LR.3728.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:13.672396519Z 240 PC: 13e37 | UNKNOWN!
2018-12-17T22:55:22.172445852Z 53 PC: 9bf0d | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:55:22.180489975Z 37 PC: 9bf1e | Set interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:55:22.181924379Z 53 PC: 9bf23 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:22.191023557Z 37 PC: 9bf34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:22.192392027Z 53 PC: 9bf39 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:55:22.193698744Z 37 PC: 9bf4a | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:55:22.194980187Z 42 PC: 9bef8 | Get date 0x9bef8: mov word ptr cs:[0x726], dx
0x9befd: mov byte ptr cs:[0x728], al
0x9bf01: pop dx
0x9bf02: pop cx
0x9bf03: pop ax
0x9bf04: ret
0x9bf05: push es
0x9bf06: push bx
0x9bf07: push dx
0x9bf08: mov ax, 0x3515
0x9bf0b: int 0x21
0x9bf0d: mov word ptr [0x56b], bx
0x9bf11: mov ax, es
0x9bf13: mov word ptr [0x56d], ax
0x9bf16: mov ax, 0x2515
0x9bf19: mov dx, 0x50e
0x9bf1c: int 0x21
0x9bf1e: mov ax, 0x3521
0x9bf21: int 0x21
0x9bf23: mov word ptr [0x6d2], bx
2018-12-17T22:55:22.197502587Z 47 PC: 9bb3f | Get disk transfer address
2018-12-17T22:55:22.198589696Z 26 PC: 9bb55 | Set disk transfer address
2018-12-17T22:55:22.19965827Z 78 PC: 9c0a0 | Find first file
2018-12-17T22:55:22.211035663Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.212321777Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.214174834Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.217786248Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.219457335Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.226868822Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.234714949Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.251827416Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.261143085Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.264035658Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.26641269Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.268459855Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.276219055Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.286554398Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.287834818Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.29037386Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.292032998Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.293518691Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.295143348Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.296552202Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.299152869Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.303166622Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.310008551Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.317517667Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.318747603Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.320652673Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.321896903Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.327802083Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.335890291Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.336912784Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.33931781Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.340855721Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.341808781Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.342730679Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.34435829Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.349506247Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.353164456Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.359797724Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.363994773Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.365163797Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.366833701Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.36803946Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.372456618Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.384989348Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.386399296Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.38919264Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.391318676Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.392589431Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.393766571Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.395751654Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.40626657Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.415942712Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.426653888Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.433443745Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.435005163Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.436805955Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.43907307Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.445849153Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.455939899Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.457878253Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.460794564Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.46245124Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.464223878Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.465660474Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.467273773Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.478088881Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.487718074Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.497752248Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.503608009Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.504610245Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.506176767Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.50794868Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.514541924Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.526367741Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.527674574Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.53010232Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.531030323Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.532377707Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.533440685Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.534516248Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.544824866Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.553150691Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.5626347Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.569180867Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.570438368Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.571593389Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.573647396Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.580270197Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.592081509Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.593621361Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.596170472Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.597286812Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.599409421Z 53 PC: 9bb09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.600500972Z 37 PC: 9bb1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.601798045Z 54 PC: 9c41b | Get free disk space
2018-12-17T22:55:22.611938564Z 67 PC: 9c432 | Get or set file attributes
2018-12-17T22:55:22.617655048Z 67 PC: 9c43f | Get or set file attributes
2018-12-17T22:55:22.627385606Z 61 PC: 9c449 | Open file
2018-12-17T22:55:22.63503468Z 87 PC: 9c459 | Get or set file date and time
2018-12-17T22:55:22.636694057Z 66 PC: 9bb8a | Move file pointer
2018-12-17T22:55:22.638386533Z 87 PC: 9c4cc | Get or set file date and time
2018-12-17T22:55:22.640939673Z 62 PC: 9c4d2 | Close file
2018-12-17T22:55:22.648202699Z 67 PC: 9c4d8 | Get or set file attributes
2018-12-17T22:55:22.660391207Z 37 PC: 9bb32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:22.662604092Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.66558152Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.666751064Z 47 PC: 9c3aa | Get disk transfer address
2018-12-17T22:55:22.668973557Z 79 PC: 9c0a0 | Find next file
2018-12-17T22:55:22.672364887Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.673799973Z 78 PC: 9c0a0 | Find first file
2018-12-17T22:55:22.680196529Z 47 PC: 9c0b2 | Get disk transfer address
2018-12-17T22:55:22.681654382Z 26 PC: 9bb6b | Set disk transfer address
2018-12-17T22:55:22.682880299Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00001004h/0000004100d bytes. ')
2018-12-17T22:55:22.688744575Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:55:22.690012417Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:55:22.696382975Z 93 PC: 12afe | File sharing functions
2018-12-17T22:55:22.699198741Z 9 PC: 12a86 | Display string (String= 'Size change=0E90h/03728d. ')
2018-12-17T22:55:22.703478352Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')