Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Crawen.8516

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:26.534945087Z 53 PC: 14932 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:26.536472864Z 53 PC: 14932 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:26.537371894Z 53 PC: 14932 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:26.538333119Z 53 PC: 14932 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:26.53949786Z 53 PC: 14932 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:26.540877224Z 53 PC: 14932 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:26.541814261Z 53 PC: 14932 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:26.542646426Z 53 PC: 14932 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:26.544186189Z 53 PC: 14932 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:26.545377551Z 53 PC: 14932 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:26.546559858Z 53 PC: 14932 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:26.548106299Z 53 PC: 14932 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:26.549490978Z 53 PC: 14932 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:26.551312287Z 53 PC: 14932 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:26.553285877Z 53 PC: 14932 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:26.554543218Z 53 PC: 14932 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:26.55579077Z 53 PC: 14932 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:26.55754749Z 53 PC: 14932 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:26.558827609Z 53 PC: 14932 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:26.560154145Z 37 PC: 14947 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:26.575886444Z 37 PC: 1494f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:26.578500815Z 37 PC: 14957 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:26.579774946Z 37 PC: 1495f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:26.582037804Z 68 PC: 14ccf | I/O control for devices (Set for = '')
2018-12-17T22:44:26.612572545Z 37 PC: 14355 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:26.61424448Z 42 PC: 13fa7 | Get date 0x13fa7: xor ah, ah
0x13fa9: les di, ptr [bp + 6]
0x13fac: stosw word ptr es:[di], ax
0x13fad: mov al, dl
0x13faf: les di, ptr [bp + 0xa]
0x13fb2: stosw word ptr es:[di], ax
0x13fb3: mov al, dh
0x13fb5: les di, ptr [bp + 0xe]
0x13fb8: stosw word ptr es:[di], ax
0x13fb9: xchg ax, cx
0x13fba: les di, ptr [bp + 0x12]
0x13fbd: stosw word ptr es:[di], ax
0x13fbe: pop bp
0x13fbf: retf 0x10
0x13fc2: push bp
0x13fc3: mov bp, sp
0x13fc5: mov cx, word ptr [bp + 0xa]
0x13fc8: mov dh, byte ptr [bp + 8]
0x13fcb: mov dl, byte ptr [bp + 6]
0x13fce: mov ah, 0x2b
2018-12-17T22:44:26.61896133Z 48 PC: 15659 | Get DOS version
2018-12-17T22:44:26.621318146Z 61 PC: 15448 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:44:26.628844439Z 66 PC: 155e4 | Move file pointer
2018-12-17T22:44:26.630254583Z 66 PC: 155f2 | Move file pointer
2018-12-17T22:44:26.633072369Z 66 PC: 15600 | Move file pointer
2018-12-17T22:44:26.635104749Z 66 PC: 1557a | Move file pointer
2018-12-17T22:44:26.637077248Z 63 PC: 154da | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:44:26.64089333Z 63 PC: 154da | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:44:26.644124403Z 63 PC: 154da | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:44:26.64719767Z 63 PC: 154da | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:44:26.650921249Z 62 PC: 15498 | Close file
2018-12-17T22:44:26.672179574Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:26.673263701Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:26.674999931Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:26.676084916Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:26.677240239Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:26.678564417Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:26.679805532Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:26.681017316Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:26.68242451Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:26.683610955Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:26.684821965Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:26.685963582Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:26.687258081Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:26.688489237Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:26.689712942Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:26.691383601Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:26.692624923Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:26.693860305Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:26.695544639Z 37 PC: 14a46 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:26.696768835Z 76 PC: 14a85 | Terminate with return code (Return code = '0')