Sample viewer

vx.netlux.org/Virus.DOS.LR.2884

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:28.740252873Z 240 PC: 17b83 | UNKNOWN!
2018-12-17T23:06:28.742218114Z 53 PC: 9ddcc | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T23:06:28.743640718Z 37 PC: 9dddd | Set interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T23:06:28.744945805Z 53 PC: 9dde2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:28.754998209Z 37 PC: 9ddf3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:28.756644957Z 53 PC: 9ddf8 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:06:28.758276824Z 37 PC: 9de09 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:06:28.760007871Z 42 PC: 9ddb7 | Get date 0x9ddb7: mov byte ptr cs:[0x585], dl
0x9ddbc: mov byte ptr cs:[0x586], al
0x9ddc0: pop dx
0x9ddc1: pop cx
0x9ddc2: pop ax
0x9ddc3: ret
0x9ddc4: push es
0x9ddc5: push bx
0x9ddc6: push dx
0x9ddc7: mov ax, 0x3515
0x9ddca: int 0x21
0x9ddcc: mov word ptr [0x47b], bx
0x9ddd0: mov ax, es
0x9ddd2: mov word ptr [0x47d], ax
0x9ddd5: mov ax, 0x2515
0x9ddd8: mov dx, 0x42d
0x9dddb: int 0x21
0x9dddd: mov ax, 0x3521
0x9dde0: int 0x21
0x9dde2: mov word ptr [0x581], bx
2018-12-17T23:06:28.763826095Z 47 PC: 9dadf | Get disk transfer address
2018-12-17T23:06:28.76513186Z 26 PC: 9daf5 | Set disk transfer address
2018-12-17T23:06:28.766440053Z 78 PC: 9df36 | Find first file
2018-12-17T23:06:28.773261639Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:28.775033284Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:28.776695449Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.779812178Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.781417836Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:28.790423098Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:28.797115874Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:28.813828825Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:28.821556284Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:28.829424402Z 62 PC: 9e23c | Close file
2018-12-17T23:06:28.831603577Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:28.841532801Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.84340334Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:28.846172837Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:28.8474707Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:28.849863314Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.851443958Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.852913015Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:28.864193443Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:28.873012162Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:28.882612481Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:28.88957937Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:28.891074059Z 62 PC: 9e23c | Close file
2018-12-17T23:06:28.892794041Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:28.903615806Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.904849552Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:28.907454584Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:28.908754399Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:28.910152579Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.911274098Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.912555173Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:28.922779449Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:28.932294411Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:28.94205557Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:28.948582231Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:28.949857658Z 62 PC: 9e23c | Close file
2018-12-17T23:06:28.952816476Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:28.972352494Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.973519153Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:28.976251572Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:28.978020755Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:28.979207237Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.980332366Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:28.981720158Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:28.98465299Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:28.99561597Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:29.010322182Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:29.018206226Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:29.019985441Z 62 PC: 9e23c | Close file
2018-12-17T23:06:29.022526806Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:29.034628837Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.035944352Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:29.039977353Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:29.042095605Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:29.04367956Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.046838476Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.048499644Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:29.058548626Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:29.065063742Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:29.074997284Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:29.081615879Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:29.083891794Z 62 PC: 9e23c | Close file
2018-12-17T23:06:29.086004068Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:29.096236585Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.098751871Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:29.101747515Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:29.103317158Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:29.105879016Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.107437535Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.108893347Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:29.119704103Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:29.131046434Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:29.14124511Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:29.148675359Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:29.150557269Z 62 PC: 9e23c | Close file
2018-12-17T23:06:29.152597576Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:29.163200541Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.1649441Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:29.16778434Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:29.169949885Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:29.171499083Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.17339221Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.174795077Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:29.184250379Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:29.19540144Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:29.205254576Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:29.212406817Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:29.214144663Z 62 PC: 9e23c | Close file
2018-12-17T23:06:29.215975132Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:29.226520131Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.227742849Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:29.230343354Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:29.232615119Z 47 PC: 9e138 | Get disk transfer address
2018-12-17T23:06:29.233867978Z 53 PC: 9daa9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.235033444Z 37 PC: 9dabd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.237624285Z 54 PC: 9e1a5 | Get free disk space
2018-12-17T23:06:29.246490421Z 67 PC: 9e1bc | Get or set file attributes
2018-12-17T23:06:29.25720419Z 67 PC: 9e1c9 | Get or set file attributes
2018-12-17T23:06:29.268575028Z 61 PC: 9e1d0 | Open file (Filename = '')
2018-12-17T23:06:29.275459257Z 87 PC: 9e1dd | Get or set file date and time
2018-12-17T23:06:29.277233721Z 62 PC: 9e23c | Close file
2018-12-17T23:06:29.279754198Z 67 PC: 9e242 | Get or set file attributes
2018-12-17T23:06:29.289614773Z 37 PC: 9dad2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.290756523Z 79 PC: 9df36 | Find next file
2018-12-17T23:06:29.293817954Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:29.295043915Z 78 PC: 9df36 | Find first file
2018-12-17T23:06:29.301000111Z 47 PC: 9df48 | Get disk transfer address
2018-12-17T23:06:29.303075619Z 26 PC: 9db0b | Set disk transfer address
2018-12-17T23:06:29.304563036Z 9 PC: 12a47 | Display string (String= 'This GOAT file was generated by Andreas Marx. ROSEGOAT by RR! (23.08.1998) File: ROSE001.COM - 20.000 (4E20h) bytes length! ')