Sample viewer

vx.netlux.org/Virus.DOS.Sebal.730

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:15:55.33467984Z 250 PC: 141d3 | UNKNOWN!
2018-12-17T23:15:55.335916824Z 53 PC: 14204 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:15:55.337527091Z 37 PC: 14214 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:15:55.338678114Z 53 PC: 14219 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:15:55.339867891Z 44 PC: 14225 | Get time 0x14225: add ch, 2
0x14228: mov byte ptr [0x346], ch
0x1422c: pop es
0x1422d: pop si
0x1422e: mov si, es
0x14230: mov di, cs
0x14232: cmp si, di
0x14234: je 0x14269
0x14236: cli
0x14237: mov word ptr [0x33a], ss
0x1423b: mov word ptr [0x33c], sp
0x1423f: push cs
0x14240: pop ss
0x14241: mov sp, 0x3d5
0x14244: sti
0x14245: mov bx, bp
0x14247: mov cl, 4
0x14249: shr bx, cl
0x1424b: inc bx
0x1424c: mov ah, 0x4a
2018-12-17T23:15:55.343179445Z 74 PC: 14250 | Reallocate memory
2018-12-17T23:15:55.344993856Z 75 PC: 1425f | Execute program
2018-12-17T23:15:55.352005765Z 73 PC: 1426f | Release memory
2018-12-17T23:15:55.354750384Z 77 PC: 14273 | Get program return code
2018-12-17T23:15:55.356376902Z 49 PC: 1427a | Terminate and stay resident (Return code = '0' | Memory size = '4096')