Sample viewer

vx.netlux.org/Trojan.DOS.Sabil

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:30.100889008Z 48 PC: 1653c | Get DOS version
2018-12-17T22:20:30.102749033Z 74 PC: 1658c | Reallocate memory
2018-12-17T22:20:30.105846336Z 48 PC: 165f0 | Get DOS version
2018-12-17T22:20:30.107649831Z 53 PC: 165f8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:30.111216549Z 37 PC: 1660a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:30.11336046Z 68 PC: 1669b | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T22:20:30.115284027Z 68 PC: 1669b | I/O control for devices
2018-12-17T22:20:30.117271682Z 68 PC: 1669b | I/O control for devices
2018-12-17T22:20:30.119762165Z 68 PC: 1669b | I/O control for devices
2018-12-17T22:20:30.121779263Z 68 PC: 1669b | I/O control for devices
2018-12-17T22:20:30.123655692Z 53 PC: 148b2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:30.134470837Z 53 PC: 148bf | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:20:30.136983653Z 53 PC: 148cc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:30.139485517Z 37 PC: 148e1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:30.142280699Z 37 PC: 148e9 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:20:30.144269547Z 37 PC: 148f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:30.146019761Z 53 PC: 15370 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:20:30.14811966Z 53 PC: 1537d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:20:30.150430672Z 53 PC: 1538c | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:20:30.151930354Z 37 PC: 15399 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:20:30.154037107Z 53 PC: 153a0 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:20:30.158096065Z 37 PC: 153ad | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:20:30.16071419Z 53 PC: 153b9 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:20:30.166986119Z 48 PC: 1547b | Get DOS version
2018-12-17T22:20:30.169895791Z 68 PC: 14828 | I/O control for devices (Set for = '��������')
2018-12-17T22:20:30.172668774Z 68 PC: 14828 | I/O control for devices (Set for = '')
2018-12-17T22:20:30.1746433Z 51 PC: 14846 | Get or set Ctrl-Break
2018-12-17T22:20:30.17722385Z 51 PC: 14852 | Get or set Ctrl-Break
2018-12-17T22:20:30.187262495Z 61 PC: 13258 | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:20:30.195972651Z 68 PC: 131b1 | I/O control for devices (Set for = ':;<=>[]|')
2018-12-17T22:20:30.198444954Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.200397776Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.202551033Z 63 PC: 13054 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:20:30.206735132Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.208809103Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.210936626Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.218476681Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.220692166Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.22274177Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.225294199Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.227579781Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.229748187Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.232113866Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.234519766Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.236639395Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.23884071Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.241347187Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.243169537Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.244993358Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.24752556Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.24925456Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.250930984Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.253269033Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.255418331Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.25759371Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.260320421Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.263236955Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.265183164Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.268221575Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.270342773Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.272517966Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.275392119Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.277476645Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.279566455Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.282470428Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.285773189Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.28792694Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.289963183Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.293061872Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.295184306Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.297284196Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.300972022Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.302770189Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.304555076Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.307621027Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.309612878Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.3116266Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.314545568Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.316924961Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.318961975Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.321755527Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.324059107Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.32608544Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.328282025Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.331114182Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.333107063Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.335119791Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.338145389Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.340146012Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.342164901Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.344986076Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.347284179Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.349294668Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.35206289Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.354407992Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.356425312Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.358631043Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.361448889Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.363474536Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.36547684Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.368467325Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.370495764Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.372483333Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.375296936Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.379837223Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.382777317Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.385613799Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.387950073Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.390040365Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.392318585Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.395263675Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.397338261Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.399424622Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.402519473Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.404600005Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.406687961Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.409598238Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.412000729Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.414121103Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.417004537Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.419402375Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.421482045Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.423764055Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.426632965Z 63 PC: 13054 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:20:30.429171512Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.432341977Z 64 PC: 1307a | Write file or device (Write 86 bytes on handle 5)
2018-12-17T22:20:30.436839066Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:20:30.438853807Z 62 PC: 1308b | Close file
2018-12-17T22:20:30.790904841Z 37 PC: 1564b | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:20:30.793489558Z 53 PC: 15652 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:20:30.795313194Z 37 PC: 1565f | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:20:30.796949596Z 37 PC: 1566a | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:20:30.798979325Z 37 PC: 15675 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:20:30.800204316Z 51 PC: 1485d | Get or set Ctrl-Break
2018-12-17T22:20:30.80142414Z 37 PC: 14adf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:30.80406117Z 37 PC: 14ae9 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:20:30.805554669Z 37 PC: 14af3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:30.80736275Z 37 PC: 1674c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:30.810517372Z 76 PC: 16735 | Terminate with return code (Return code = '0')