Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Sebek.4407

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:30.12913443Z 53 PC: 1326a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:30.131234696Z 53 PC: 1326a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:30.136399692Z 53 PC: 1326a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:30.138329969Z 53 PC: 1326a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:30.139821462Z 53 PC: 1326a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:30.143485488Z 53 PC: 1326a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:30.145521244Z 53 PC: 1326a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:30.147782482Z 53 PC: 1326a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:30.153584746Z 53 PC: 1326a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:30.155356846Z 53 PC: 1326a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:30.158042233Z 53 PC: 1326a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:30.160770038Z 53 PC: 1326a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:30.163301195Z 53 PC: 1326a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:30.165088694Z 53 PC: 1326a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:30.167141482Z 53 PC: 1326a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:30.169482411Z 53 PC: 1326a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:30.171360159Z 53 PC: 1326a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:30.173262604Z 53 PC: 1326a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:30.175728498Z 53 PC: 1326a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:30.177527008Z 37 PC: 1327f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:30.17926826Z 37 PC: 13287 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:30.181741307Z 37 PC: 1328f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:30.183354749Z 37 PC: 13297 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:30.185624103Z 68 PC: 13c49 | I/O control for devices (Set for = '�')
2018-12-17T23:00:30.188217878Z 44 PC: 13d80 | Get time 0x13d80: mov word ptr [0x1f0], cx
0x13d84: mov word ptr [0x1f2], dx
0x13d88: retf
0x13d89: mov bx, sp
0x13d8b: mov dx, ds
0x13d8d: lds si, ptr ss:[bx + 0xa]
0x13d91: les di, ptr ss:[bx + 6]
0x13d95: mov cx, word ptr ss:[bx + 4]
0x13d99: cld
0x13d9a: cmp si, di
0x13d9c: jae 0x13da5
0x13d9e: add si, cx
0x13da0: add di, cx
0x13da2: dec si
0x13da3: dec di
0x13da4: std
0x13da5: rep movsb byte ptr es:[di], byte ptr [si]
0x13da7: cld
0x13da8: mov ds, dx
0x13daa: retf 0xa
2018-12-17T23:00:30.191215591Z 54 PC: 12e19 | Get free disk space
2018-12-17T23:00:30.213502241Z 26 PC: 13005 | Set disk transfer address
2018-12-17T23:00:30.216707234Z 78 PC: 13011 | Find first file
2018-12-17T23:00:30.2255175Z 26 PC: 13005 | Set disk transfer address
2018-12-17T23:00:30.227166679Z 78 PC: 13011 | Find first file
2018-12-17T23:00:30.234809611Z 48 PC: 1388e | Get DOS version
2018-12-17T23:00:30.237120123Z 61 PC: 13c2d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:30.245007435Z 60 PC: 13c2d | Create or truncate file
2018-12-17T23:00:30.256736336Z 68 PC: 13c49 | I/O control for devices (Set for = '<�t������$�&,��-�����<����')
2018-12-17T23:00:30.259693803Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.263085497Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.266318943Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.270525037Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.273860014Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.291513258Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.295591131Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.298944673Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.302087799Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.310451887Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.315986617Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.319899661Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.324528539Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.335239126Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.339708675Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.343759127Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.349915506Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.361522287Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.364680371Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.368452279Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.371835928Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.379399581Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.387309214Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.390381067Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.393434886Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.402310204Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.405310072Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.408119661Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.411346274Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.419005247Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.422993281Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.426433095Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.432490839Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.435369338Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.438390265Z 63 PC: 135d6 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:00:30.442864613Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.44746608Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.45091973Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.45516616Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.45900843Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.4677624Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.471925724Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.475753657Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.479722535Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.489605558Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.493960611Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.49741898Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.500911884Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.51033941Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.513782701Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.517217715Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.521568832Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.530756587Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.534152298Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.538169468Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.541861555Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.550857741Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.555410696Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.558690239Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.563060302Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.571714565Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.575323787Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.578495206Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.581676545Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.590655487Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.59408398Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.597405162Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.601844604Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.610890132Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.614216122Z 64 PC: 13608 | Write file or device (Write 128 bytes on handle 6)
2018-12-17T23:00:30.618416626Z 62 PC: 13647 | Close file
2018-12-17T23:00:30.620536399Z 64 PC: 13608 | Write file or device (Write 15 bytes on handle 6)
2018-12-17T23:00:30.623539172Z 62 PC: 13647 | Close file
2018-12-17T23:00:30.634529645Z 48 PC: 1388e | Get DOS version
2018-12-17T23:00:30.636595136Z 53 PC: 131dc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:30.638032227Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:30.640461802Z 53 PC: 131dc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:30.642118977Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:30.64375429Z 53 PC: 131dc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:30.645402327Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:30.647788771Z 53 PC: 131dc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:30.649197568Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:30.650569576Z 53 PC: 131dc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:30.653702614Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:30.655315946Z 53 PC: 131dc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:30.656942062Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:30.659489379Z 53 PC: 131dc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:30.660966975Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:30.662274622Z 53 PC: 131dc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:30.665394846Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:30.667000012Z 53 PC: 131dc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:30.668700528Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:30.671052758Z 53 PC: 131dc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:30.672741341Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:30.674404617Z 53 PC: 131dc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:30.677268138Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:30.678926294Z 53 PC: 131dc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:30.680527473Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:30.683021249Z 53 PC: 131dc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:30.684598533Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:30.68613507Z 53 PC: 131dc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:30.68881703Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:30.690420854Z 53 PC: 131dc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:30.691969975Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:30.694589869Z 53 PC: 131dc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:30.696169336Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:30.697702217Z 53 PC: 131dc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:30.701506426Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:30.703063873Z 53 PC: 131dc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:30.704619817Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:30.70716522Z 53 PC: 131dc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:30.709210283Z 37 PC: 131e5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:30.711487312Z 41 PC: 1312b | Parse filename
2018-12-17T23:00:30.713707334Z 41 PC: 13139 | Parse filename
2018-12-17T23:00:30.716432996Z 75 PC: 13144 | Execute program
2018-12-17T23:00:30.741678577Z 80 PC: 17cb9 | Set current PSP
2018-12-17T23:00:30.743471355Z 48 PC: 17cbe | Get DOS version
2018-12-17T23:00:30.747730028Z 99 PC: 1e4a0 | Get DBCS lead byte table pointer
2018-12-17T23:00:30.751091786Z 101 PC: 17d44 | Get extended country info
2018-12-17T23:00:30.752985464Z 99 PC: 17d4a | Get DBCS lead byte table pointer
2018-12-17T23:00:30.755496943Z 74 PC: 17dac | Reallocate memory
2018-12-17T23:00:30.757499737Z 25 PC: 17de3 | Get default drive
2018-12-17T23:00:30.759214609Z 37 PC: 178a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:00:30.761802453Z 37 PC: 178aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:30.763995263Z 37 PC: 178b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:30.776899192Z 74 PC: 16a4c | Reallocate memory
2018-12-17T23:00:30.779812817Z 72 PC: 16a8d | Allocate memory
2018-12-17T23:00:30.781563266Z 72 PC: 16ac5 | Allocate memory
2018-12-17T23:00:30.783534411Z 72 PC: 16acd | Allocate memory