Sample viewer

vx.netlux.org/Virus.DOS.Hanko.4087

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:28.591957136Z 42 PC: 1329e | Get date 0x1329e: cmp al, 5
0x132a0: jne 0x132ae
0x132a2: cmp dl, 0xd
0x132a5: jne 0x132ae
0x132a7: call 0x132af
0x132aa: xor ah, ah
0x132ac: int 0x16
0x132ae: ret
0x132af: push ds
0x132b0: push es
0x132b1: mov ah, 1
0x132b3: mov ch, 0x20
0x132b5: int 0x10
0x132b7: mov ax, 0xb800
0x132ba: mov es, ax
0x132bc: xor di, di
0x132be: mov cx, 0x7d0
0x132c1: mov ax, 0x1e20
0x132c4: rep stosd dword ptr es:[di], eax
0x132c6: mov di, 0x640
2018-12-17T22:33:28.595301183Z 98 PC: 13159 | Get current PSP
2018-12-17T22:33:28.596785281Z 47 PC: 9e6ff | Get disk transfer address
2018-12-17T22:33:28.597925435Z 26 PC: 9e6ff | Set disk transfer address
2018-12-17T22:33:28.599023277Z 98 PC: 9e6ff | Get current PSP
2018-12-17T22:33:28.600140271Z 78 PC: 9e6ff | Find first file
2018-12-17T22:33:28.611125685Z 61 PC: 9e6ff | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:33:28.618608779Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:28.620227729Z 63 PC: 9e6ff | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:33:28.627155037Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:28.6672444Z 64 PC: 9e6ff | Write file or device (Write 4051 bytes on handle 5)
2018-12-17T22:33:29.088718018Z 64 PC: 9e6ff | Write file or device (Write 36 bytes on handle 5)
2018-12-17T22:33:29.092146852Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.093937Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.09610045Z 64 PC: 9e6ff | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:33:29.099638991Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.101666183Z 62 PC: 9e6ff | Close file
2018-12-17T22:33:29.110590656Z 79 PC: 9e6ff | Find next file
2018-12-17T22:33:29.114262365Z 61 PC: 9e6ff | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T22:33:29.121949698Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.124232682Z 63 PC: 9e6ff | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:33:29.130711928Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.183357533Z 64 PC: 9e6ff | Write file or device (Write 4051 bytes on handle 5)
2018-12-17T22:33:29.194947745Z 64 PC: 9e6ff | Write file or device (Write 36 bytes on handle 5)
2018-12-17T22:33:29.197939624Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.199436211Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.212746473Z 64 PC: 9e6ff | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:33:29.215939469Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.217617012Z 62 PC: 9e6ff | Close file
2018-12-17T22:33:29.225563428Z 79 PC: 9e6ff | Find next file
2018-12-17T22:33:29.229998882Z 61 PC: 9e6ff | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T22:33:29.238208599Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.240238822Z 63 PC: 9e6ff | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:33:29.24774829Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.300776243Z 64 PC: 9e6ff | Write file or device (Write 4051 bytes on handle 5)
2018-12-17T22:33:29.316434707Z 64 PC: 9e6ff | Write file or device (Write 36 bytes on handle 5)
2018-12-17T22:33:29.319937489Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.321611612Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.323191332Z 64 PC: 9e6ff | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:33:29.326885285Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.328471387Z 62 PC: 9e6ff | Close file
2018-12-17T22:33:29.336886709Z 79 PC: 9e6ff | Find next file
2018-12-17T22:33:29.350383367Z 61 PC: 9e6ff | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T22:33:29.358787935Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.360817755Z 63 PC: 9e6ff | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:33:29.367809718Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.417899993Z 64 PC: 9e6ff | Write file or device (Write 4051 bytes on handle 5)
2018-12-17T22:33:29.428016075Z 64 PC: 9e6ff | Write file or device (Write 36 bytes on handle 5)
2018-12-17T22:33:29.430785275Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.432392386Z 66 PC: 9e6ff | Move file pointer
2018-12-17T22:33:29.433662268Z 64 PC: 9e6ff | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:33:29.437074886Z 87 PC: 9e6ff | Get or set file date and time
2018-12-17T22:33:29.438971893Z 62 PC: 9e6ff | Close file
2018-12-17T22:33:29.449064331Z 79 PC: 9e6ff | Find next file
2018-12-17T22:33:29.453106407Z 78 PC: 9e6ff | Find first file
2018-12-17T22:33:29.461245648Z 26 PC: 9e6ff | Set disk transfer address
2018-12-17T22:33:29.463168323Z 76 PC: 12e38 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":13,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5991,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:12.634483105Z 42 PC: 1329e | Get date 0x1329e: cmp al, 5
0x132a0: jne 0x132ae
0x132a2: cmp dl, 0xd
0x132a5: jne 0x132ae
0x132a7: call 0x132af
0x132aa: xor ah, ah
0x132ac: int 0x16
0x132ae: ret
0x132af: push ds
0x132b0: push es
0x132b1: mov ah, 1
0x132b3: mov ch, 0x20
0x132b5: int 0x10
0x132b7: mov ax, 0xb800
0x132ba: mov es, ax
0x132bc: xor di, di
0x132be: mov cx, 0x7d0
0x132c1: mov ax, 0x1e20
0x132c4: rep stosd dword ptr es:[di], eax
0x132c6: mov di, 0x640

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5991,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:12.882384815Z 42 PC: 1329e | Get date 0x1329e: cmp al, 5
0x132a0: jne 0x132ae
0x132a2: cmp dl, 0xd
0x132a5: jne 0x132ae
0x132a7: call 0x132af
0x132aa: xor ah, ah
0x132ac: int 0x16
0x132ae: ret
0x132af: push ds
0x132b0: push es
0x132b1: mov ah, 1
0x132b3: mov ch, 0x20
0x132b5: int 0x10
0x132b7: mov ax, 0xb800
0x132ba: mov es, ax
0x132bc: xor di, di
0x132be: mov cx, 0x7d0
0x132c1: mov ax, 0x1e20
0x132c4: rep stosd dword ptr es:[di], eax
0x132c6: mov di, 0x640
2018-12-25T11:58:12.885385248Z 98 PC: 13159 | Get current PSP
2018-12-25T11:58:12.886667425Z 47 PC: 9e6ff | Get disk transfer address
2018-12-25T11:58:12.887628342Z 26 PC: 9e6ff | Set disk transfer address (See above)
2018-12-25T11:58:12.888876916Z 98 PC: 9e6ff | Get current PSP (See above)
2018-12-25T11:58:12.889738292Z 78 PC: 9e6ff | Find first file (See above)
2018-12-25T11:58:12.898595579Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:12.906716569Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:12.90799725Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:12.92018414Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:12.956879183Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.811136321Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.813819505Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.816035826Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.817892292Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.820948223Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.823584548Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:14.837795803Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:14.841160703Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:14.853253155Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.855224972Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:14.860558149Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.905020151Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.915055795Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.917577298Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.918951329Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.920936908Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.924010623Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.925353008Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:14.933521848Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:14.948751918Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:14.955456525Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.964750118Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:14.968410128Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.988048061Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.995986384Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.997846916Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.999563547Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.001148263Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.003867983Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:15.005233361Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:15.013158028Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:15.016822053Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:15.023393258Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:15.025871708Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:15.031270569Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.068300848Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.07846323Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.081299777Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.082809678Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.084818854Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.087408668Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:15.088853798Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:15.096420969Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:15.099563013Z 78 PC: 9e6ff | Find first file (See above)
2018-12-25T11:58:15.105940024Z 26 PC: 9e6ff | Set disk transfer address (See above)
2018-12-25T11:58:15.1088128Z 76 PC: 12e38 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5991,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:12.907124873Z 42 PC: 1329e | Get date 0x1329e: cmp al, 5
0x132a0: jne 0x132ae
0x132a2: cmp dl, 0xd
0x132a5: jne 0x132ae
0x132a7: call 0x132af
0x132aa: xor ah, ah
0x132ac: int 0x16
0x132ae: ret
0x132af: push ds
0x132b0: push es
0x132b1: mov ah, 1
0x132b3: mov ch, 0x20
0x132b5: int 0x10
0x132b7: mov ax, 0xb800
0x132ba: mov es, ax
0x132bc: xor di, di
0x132be: mov cx, 0x7d0
0x132c1: mov ax, 0x1e20
0x132c4: rep stosd dword ptr es:[di], eax
0x132c6: mov di, 0x640
2018-12-25T11:58:12.910183301Z 98 PC: 13159 | Get current PSP
2018-12-25T11:58:12.911515115Z 47 PC: 9e6ff | Get disk transfer address
2018-12-25T11:58:12.913136942Z 26 PC: 9e6ff | Set disk transfer address (See above)
2018-12-25T11:58:12.91482096Z 98 PC: 9e6ff | Get current PSP (See above)
2018-12-25T11:58:12.915735369Z 78 PC: 9e6ff | Find first file (See above)
2018-12-25T11:58:12.924594476Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:12.93143418Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:12.932804079Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:12.938432767Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:12.971128396Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.804311255Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.806918824Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.808392809Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.810412894Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.81268593Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.813961126Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:14.819445484Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:14.821720185Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:14.842964049Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.845257767Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:14.85436728Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.898514376Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.910160624Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.913757473Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.915090835Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.917443614Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.919622149Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.92124957Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:14.927857808Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:14.930264584Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:14.934912343Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.936339765Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:14.940417028Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.962280498Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.980498542Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.983887916Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.985229155Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:14.987162134Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:14.990231418Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:14.991631668Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:14.998673709Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:15.002339876Z 61 PC: 9e6ff | Open file (See above)
2018-12-25T11:58:15.008876492Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:15.010150413Z 63 PC: 9e6ff | Read file or device (See above)
2018-12-25T11:58:15.016201234Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.055489965Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.06456639Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.06736854Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.068909026Z 66 PC: 9e6ff | Move file pointer (See above)
2018-12-25T11:58:15.070460771Z 64 PC: 9e6ff | Write file or device (See above)
2018-12-25T11:58:15.073404038Z 87 PC: 9e6ff | Get or set file date and time (See above)
2018-12-25T11:58:15.07476186Z 62 PC: 9e6ff | Close file (See above)
2018-12-25T11:58:15.08160144Z 79 PC: 9e6ff | Find next file (See above)
2018-12-25T11:58:15.08493611Z 78 PC: 9e6ff | Find first file (See above)
2018-12-25T11:58:15.091167443Z 26 PC: 9e6ff | Set disk transfer address (See above)
2018-12-25T11:58:15.093629128Z 76 PC: 12e38 | Terminate with return code (Return code = '0')