Sample viewer

vx.netlux.org/Virus.DOS.Sentinel.5402

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:05:54.18693011Z 53 PC: 14732 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.189736736Z 53 PC: 14732 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:54.191395079Z 53 PC: 14732 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:54.192921605Z 53 PC: 14732 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:54.195035339Z 53 PC: 14732 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.200477573Z 53 PC: 14732 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.202710264Z 53 PC: 14732 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:54.204521309Z 53 PC: 14732 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:54.206384778Z 53 PC: 14732 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:54.20745315Z 53 PC: 14732 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:54.208737242Z 53 PC: 14732 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:54.212041329Z 53 PC: 14732 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:54.21946133Z 53 PC: 14732 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:54.221726435Z 53 PC: 14732 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:54.223960797Z 53 PC: 14732 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:54.225453046Z 53 PC: 14732 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:54.230639013Z 53 PC: 14732 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:54.231827958Z 53 PC: 14732 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.233216Z 53 PC: 14732 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:54.239190182Z 37 PC: 14747 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.240318006Z 37 PC: 1474f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.241490103Z 37 PC: 14757 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.244967501Z 37 PC: 1475f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.247170539Z 68 PC: 14a7c | I/O control for devices (Set for = '')
2018-12-17T22:05:54.250355802Z 53 PC: 146af | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.25365112Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.255055599Z 53 PC: 146af | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:54.25655524Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:54.259046535Z 53 PC: 146af | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:54.260145945Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:54.261164651Z 53 PC: 146af | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:54.263244902Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:54.264247678Z 53 PC: 146af | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.265237546Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.266838416Z 53 PC: 146af | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.267874853Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.268830423Z 53 PC: 146af | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:54.270678769Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:54.271680342Z 53 PC: 146af | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:54.272733217Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:54.289412192Z 53 PC: 146af | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:54.292160181Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:54.293287947Z 53 PC: 146af | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:54.294854705Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:54.296071531Z 53 PC: 146af | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:54.297372215Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:54.299418839Z 53 PC: 146af | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:54.30056052Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:54.301728913Z 53 PC: 146af | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:54.303489484Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:54.305998989Z 53 PC: 146af | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:54.307430652Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:54.30899192Z 53 PC: 146af | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:54.311326476Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:54.312741351Z 53 PC: 146af | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:54.314216132Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:54.316638377Z 53 PC: 146af | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:54.317972802Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:54.318935609Z 53 PC: 146af | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.320601349Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.321609351Z 53 PC: 146af | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:54.322599745Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:54.324298751Z 44 PC: 145ed | Get time 0x145ed: xor ah, ah
0x145ef: mov al, dl
0x145f1: les di, ptr [bp + 6]
0x145f4: stosw word ptr es:[di], ax
0x145f5: mov al, dh
0x145f7: les di, ptr [bp + 0xa]
0x145fa: stosw word ptr es:[di], ax
0x145fb: mov al, cl
0x145fd: les di, ptr [bp + 0xe]
0x14600: stosw word ptr es:[di], ax
0x14601: mov al, ch
0x14603: les di, ptr [bp + 0x12]
0x14606: stosw word ptr es:[di], ax
0x14607: pop bp
0x14608: retf 0x10
0x1460b: push bp
0x1460c: mov bp, sp
0x1460e: mov ch, byte ptr [bp + 0xc]
0x14611: mov cl, byte ptr [bp + 0xa]
0x14614: mov dh, byte ptr [bp + 8]
2018-12-17T22:05:54.326265172Z 42 PC: 145b7 | Get date 0x145b7: xor ah, ah
0x145b9: les di, ptr [bp + 6]
0x145bc: stosw word ptr es:[di], ax
0x145bd: mov al, dl
0x145bf: les di, ptr [bp + 0xa]
0x145c2: stosw word ptr es:[di], ax
0x145c3: mov al, dh
0x145c5: les di, ptr [bp + 0xe]
0x145c8: stosw word ptr es:[di], ax
0x145c9: xchg ax, cx
0x145ca: les di, ptr [bp + 0x12]
0x145cd: stosw word ptr es:[di], ax
0x145ce: pop bp
0x145cf: retf 0x10
0x145d2: push bp
0x145d3: mov bp, sp
0x145d5: mov cx, word ptr [bp + 0xa]
0x145d8: mov dh, byte ptr [bp + 8]
0x145db: mov dl, byte ptr [bp + 6]
0x145de: mov ah, 0x2b
2018-12-17T22:05:54.328909928Z 48 PC: 13afe | Get DOS version
2018-12-17T22:05:54.332131349Z 86 PC: 13d27 | Rename file
2018-12-17T22:05:54.34593308Z 67 PC: 13d69 | Get or set file attributes
2018-12-17T22:05:54.350470045Z 66 PC: 9e82b | Move file pointer
2018-12-17T22:05:54.352869568Z 66 PC: 9e82b | Move file pointer
2018-12-17T22:05:54.35436451Z 66 PC: 9e82b | Move file pointer
2018-12-17T22:05:54.365310608Z 87 PC: 9e82b | Get or set file date and time
2018-12-17T22:05:54.370132953Z 64 PC: 14b7f | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:05:54.375454233Z 66 PC: 9e82b | Move file pointer
2018-12-17T22:05:54.378364604Z 66 PC: 9e82b | Move file pointer
2018-12-17T22:05:54.380577311Z 66 PC: 9e82b | Move file pointer
2018-12-17T22:05:54.383015375Z 87 PC: 9e82b | Get or set file date and time
2018-12-17T22:05:54.38466173Z 64 PC: 14b7f | Write file or device (Write 41 bytes on handle 1)
2018-12-17T22:05:54.390441058Z 53 PC: 146af | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.391685637Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.393215273Z 53 PC: 146af | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:54.395253754Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:54.396278132Z 53 PC: 146af | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:54.397419731Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:54.399627444Z 53 PC: 146af | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:54.400814802Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:54.403413959Z 53 PC: 146af | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.408056623Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.409351944Z 53 PC: 146af | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.411234483Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.414491449Z 53 PC: 146af | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:54.417018484Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:54.426206746Z 53 PC: 146af | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:54.429583066Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:54.430956454Z 53 PC: 146af | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:54.432448823Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:54.434620928Z 53 PC: 146af | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:54.437897842Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:54.439276321Z 53 PC: 146af | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:54.440401203Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:54.441755317Z 53 PC: 146af | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:54.442635892Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:54.443673788Z 53 PC: 146af | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:54.445012461Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:54.445919823Z 53 PC: 146af | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:54.446834272Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:54.448393653Z 53 PC: 146af | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:54.449319979Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:54.450219984Z 53 PC: 146af | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:54.451629432Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:54.452509067Z 53 PC: 146af | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:54.453426017Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:54.454837686Z 53 PC: 146af | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.455741294Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.456601613Z 53 PC: 146af | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:54.458211045Z 37 PC: 146b8 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:54.459319692Z 64 PC: 14b7f | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:05:54.460663002Z 37 PC: 14846 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:54.462193685Z 37 PC: 14846 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:54.463076982Z 37 PC: 14846 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:54.46396399Z 37 PC: 14846 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:54.466282026Z 37 PC: 14846 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:54.473690159Z 37 PC: 14846 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:54.474964752Z 37 PC: 14846 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:54.476549546Z 37 PC: 14846 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:54.477773572Z 37 PC: 14846 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:54.480363731Z 37 PC: 14846 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:54.48329185Z 37 PC: 14846 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:54.484952094Z 37 PC: 14846 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:54.486585253Z 37 PC: 14846 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:54.488975589Z 37 PC: 14846 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:54.49041273Z 37 PC: 14846 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:54.491599495Z 37 PC: 14846 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:54.493197221Z 37 PC: 14846 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:54.494267147Z 37 PC: 14846 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:54.495285923Z 37 PC: 14846 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:54.497292327Z 76 PC: 14885 | Terminate with return code (Return code = '0')