Sample viewer

vx.netlux.org/Virus.DOS.Abbas.5660

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:04.608582684Z 53 PC: 14052 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:46:04.610373561Z 53 PC: 14061 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:46:04.611857166Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.612924289Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.61469113Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.616180972Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:46:04.619561636Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.621078975Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.622640615Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.624172499Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T22:46:04.640023982Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.642420777Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.64575439Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.646886611Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:46:04.648536335Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.64969478Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.650785449Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.652605594Z 72 PC: 12174 | Allocate memory
2018-12-17T22:46:04.654696028Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.656135816Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.658120843Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.659482475Z 72 PC: 1218d | Allocate memory
2018-12-17T22:46:04.661960577Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.66334279Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.664577313Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.666922561Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:46:04.668726716Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.670584212Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.673055102Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.674313426Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:04.675850023Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.678244376Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.679685094Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.681057229Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.692236299Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.694242201Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.695318886Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.696993919Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.698741183Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.700063155Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.702333128Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.703830242Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.705866546Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.707466694Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.709544979Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.711174888Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.713212582Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.71512875Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.716396801Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.717641982Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.719758743Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.721113816Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.722341153Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.724438717Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.726166754Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.727393683Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.728877567Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.730522017Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.73330549Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.734720692Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.736623441Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.737823549Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.739422909Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.741258027Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.742933915Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.744579757Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.747049049Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.748669762Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.75029567Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.752289846Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.75403629Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.755372106Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.757038316Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.758488925Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.760550597Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.762728845Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.764087682Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.765377218Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.769400122Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.770737732Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.771933037Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.773154255Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.774991519Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.776300646Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.77762305Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.779766802Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.781565387Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.782955138Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.78500238Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.786596819Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.788565273Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.790486995Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.792098009Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.794043445Z 62 PC: 122ab | Close file
2018-12-17T22:46:04.79782145Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.799558893Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.801232687Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.803677134Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:46:04.810516045Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.811826536Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.813598795Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.814629013Z 66 PC: 12372 | Move file pointer
2018-12-17T22:46:04.815771952Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.817069719Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.818380023Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.819457921Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T22:46:04.833196618Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.834429601Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.835456326Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.837182293Z 62 PC: 1238a | Close file
2018-12-17T22:46:04.839389343Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.840479818Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.842374063Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.843933125Z 99 PC: 98fb7 | Get DBCS lead byte table pointer
2018-12-17T22:46:04.845782208Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.847925037Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.849248509Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.850525155Z 56 PC: 937d9 | Get or set country info
2018-12-17T22:46:04.852896713Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.855176532Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.856424847Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.857651775Z 64 PC: 99228 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:46:04.863222482Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.864700661Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.866059847Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.868546939Z 25 PC: 93842 | Get default drive
2018-12-17T22:46:04.87033143Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.871517099Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.873242813Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.874808436Z 71 PC: 95abd | Get current directory
2018-12-17T22:46:04.879955659Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.882443836Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.884037788Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.884992028Z 64 PC: 99228 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:46:04.888786323Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.890012705Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.89135895Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.892952098Z 2 PC: 95a92 | Character output (Char = '3e')
2018-12-17T22:46:04.896143881Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.897297033Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.899373418Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.900502338Z 93 PC: 93900 | File sharing functions
2018-12-17T22:46:04.902234183Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.904014297Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.905490912Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.906973318Z 93 PC: 93907 | File sharing functions
2018-12-17T22:46:04.909431831Z 53 PC: 9e60d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.912107448Z 37 PC: 9e625 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.913664416Z 37 PC: 9e748 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:04.915852405Z 10 PC: 93919 | Buffered keyboard input