Sample viewer

vx.netlux.org/Virus.DOS.HPE.2272

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:03.497255827Z 26 PC: 133a7 | Set disk transfer address
2018-12-17T22:24:03.499225602Z 71 PC: 133b3 | Get current directory
2018-12-17T22:24:03.501963971Z 44 PC: 12be0 | Get time 0x12be0: in al, 0x40
0x12be2: mov ah, al
0x12be4: in al, 0x40
0x12be6: xor ax, cx
0x12be8: xor dx, ax
0x12bea: jmp 0x12c08
0x12bec: push dx
0x12bed: push cx
0x12bee: push bx
0x12bef: in al, 0x40
0x12bf1: add ax, 0x9e86
0x12bf4: mov dx, 0x83c8
0x12bf7: mov cx, 7
0x12bfa: shl ax, 1
0x12bfc: rcl dx, 1
0x12bfe: mov bl, al
0x12c00: xor bl, dh
0x12c02: jns 0x12c06
0x12c04: inc al
0x12c06: loop 0x12bfa
2018-12-17T22:24:03.504018005Z 78 PC: 133c3 | Find first file
2018-12-17T22:24:03.510075891Z 61 PC: 133e7 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:24:03.521086556Z 63 PC: 133f4 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:24:03.527454896Z 62 PC: 133f8 | Close file
2018-12-17T22:24:03.529180036Z 61 PC: 1341b | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:24:03.535892068Z 64 PC: 13448 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:24:03.547566388Z 64 PC: 1347a | Write file or device (Write 89 bytes on handle 5)
2018-12-17T22:24:03.550067541Z 64 PC: 13482 | Write file or device (Write 2272 bytes on handle 5)
2018-12-17T22:24:03.564866346Z 62 PC: 1348d | Close file
2018-12-17T22:24:03.572235572Z 79 PC: 133c3 | Find next file
2018-12-17T22:24:03.574852757Z 61 PC: 133e7 | Open file (Filename = '')
2018-12-17T22:24:03.581568632Z 63 PC: 133f4 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:24:03.587792715Z 62 PC: 133f8 | Close file
2018-12-17T22:24:03.589595732Z 61 PC: 1341b | Open file (Filename = '')
2018-12-17T22:24:03.597181304Z 64 PC: 13448 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:24:03.627227664Z 64 PC: 1347a | Write file or device (Write 85 bytes on handle 5)
2018-12-17T22:24:03.630293894Z 64 PC: 13482 | Write file or device (Write 2272 bytes on handle 5)
2018-12-17T22:24:03.639554553Z 62 PC: 1348d | Close file
2018-12-17T22:24:03.647429811Z 79 PC: 133c3 | Find next file
2018-12-17T22:24:03.650474852Z 61 PC: 133e7 | Open file (Filename = '')
2018-12-17T22:24:03.658073101Z 63 PC: 133f4 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:24:03.664388462Z 62 PC: 133f8 | Close file
2018-12-17T22:24:03.666099783Z 61 PC: 1341b | Open file (Filename = '')
2018-12-17T22:24:03.673132739Z 64 PC: 13448 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:24:03.70140806Z 64 PC: 1347a | Write file or device (Write 52 bytes on handle 5)
2018-12-17T22:24:03.704605814Z 64 PC: 13482 | Write file or device (Write 2272 bytes on handle 5)
2018-12-17T22:24:03.714710299Z 62 PC: 1348d | Close file
2018-12-17T22:24:03.722530949Z 79 PC: 133c3 | Find next file
2018-12-17T22:24:03.725326232Z 61 PC: 133e7 | Open file (Filename = '')
2018-12-17T22:24:03.732170623Z 63 PC: 133f4 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:24:03.747483801Z 62 PC: 133f8 | Close file
2018-12-17T22:24:03.749345497Z 61 PC: 1341b | Open file (Filename = '')
2018-12-17T22:24:03.756104537Z 64 PC: 13448 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:24:03.770736966Z 64 PC: 1347a | Write file or device (Write 51 bytes on handle 5)
2018-12-17T22:24:03.773468899Z 64 PC: 13482 | Write file or device (Write 2272 bytes on handle 5)
2018-12-17T22:24:03.781895204Z 62 PC: 1348d | Close file
2018-12-17T22:24:03.790901471Z 79 PC: 133c3 | Find next file
2018-12-17T22:24:03.7934729Z 61 PC: 133e7 | Open file (Filename = '')
2018-12-17T22:24:03.800125572Z 63 PC: 133f4 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:24:03.807448836Z 62 PC: 133f8 | Close file
2018-12-17T22:24:03.809396908Z 61 PC: 1341b | Open file (Filename = '')
2018-12-17T22:24:03.816287417Z 64 PC: 13448 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:24:03.827396604Z 64 PC: 1347a | Write file or device (Write 35 bytes on handle 5)
2018-12-17T22:24:03.830215225Z 64 PC: 13482 | Write file or device (Write 2272 bytes on handle 5)
2018-12-17T22:24:03.838727243Z 62 PC: 1348d | Close file
2018-12-17T22:24:03.846569399Z 59 PC: 133d5 | Change current directory
2018-12-17T22:24:03.850404123Z 26 PC: 133de | Set disk transfer address
2018-12-17T22:24:03.851362214Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:24:03.856682177Z 76 PC: 12a86 | Terminate with return code (Return code = '36')