Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Erot.5718

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:26.789986508Z 53 PC: 1390a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:26.7919781Z 53 PC: 1390a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:26.793579208Z 53 PC: 1390a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:26.794870463Z 53 PC: 1390a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:26.79616761Z 53 PC: 1390a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:26.798058653Z 53 PC: 1390a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:26.799327016Z 53 PC: 1390a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:26.800609786Z 53 PC: 1390a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:26.804563874Z 53 PC: 1390a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:26.812987249Z 53 PC: 1390a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:26.81474417Z 53 PC: 1390a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:26.817945674Z 53 PC: 1390a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:26.819842678Z 53 PC: 1390a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:26.821864907Z 53 PC: 1390a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:26.824940445Z 53 PC: 1390a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:26.826862706Z 53 PC: 1390a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:26.828755853Z 53 PC: 1390a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:26.830630625Z 53 PC: 1390a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:26.833920276Z 53 PC: 1390a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:26.835582719Z 37 PC: 1391f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:26.837342655Z 37 PC: 13927 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:26.839995589Z 37 PC: 1392f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:26.841925876Z 37 PC: 13937 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:26.844331605Z 68 PC: 14667 | I/O control for devices (Set for = '')
2018-12-17T22:50:26.853459373Z 48 PC: 14192 | Get DOS version
2018-12-17T22:50:26.855614702Z 61 PC: 13fd0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:50:26.86308169Z 66 PC: 148c5 | Move file pointer
2018-12-17T22:50:26.866273296Z 66 PC: 148d3 | Move file pointer
2018-12-17T22:50:26.868045556Z 66 PC: 148e1 | Move file pointer
2018-12-17T22:50:26.870825999Z 62 PC: 14020 | Close file
2018-12-17T22:50:26.873878283Z 48 PC: 14192 | Get DOS version
2018-12-17T22:50:26.875816815Z 61 PC: 13fd0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:50:26.883979571Z 61 PC: 13fd0 | Open file (Filename = 'prg1.exe')
2018-12-17T22:50:26.891682923Z 60 PC: 13fd0 | Create or truncate file
2018-12-17T22:50:26.910285401Z 66 PC: 14102 | Move file pointer
2018-12-17T22:50:26.912028005Z 63 PC: 140a3 | Read file or device (Read 5715 bytes on handle 5)
2018-12-17T22:50:26.920596893Z 64 PC: 140a3 | Write file or device (Write 5124 bytes on handle 6)
2018-12-17T22:50:26.930907594Z 63 PC: 140a3 | Read file or device (Read 5715 bytes on handle 5)
2018-12-17T22:50:26.933376452Z 62 PC: 14020 | Close file
2018-12-17T22:50:26.942810466Z 62 PC: 14020 | Close file
2018-12-17T22:50:26.946140321Z 53 PC: 13888 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:26.948078082Z 37 PC: 13891 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:26.949734073Z 53 PC: 13888 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:26.952093595Z 37 PC: 13891 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:26.954082983Z 53 PC: 13888 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:26.955712945Z 37 PC: 13891 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:26.957486517Z 53 PC: 13888 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:26.959913026Z 37 PC: 13891 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:26.961495709Z 53 PC: 13888 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:26.963098991Z 37 PC: 13891 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:26.96573839Z 53 PC: 13888 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:26.967354867Z 37 PC: 13891 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:26.968920979Z 53 PC: 13888 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:26.971282325Z 37 PC: 13891 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:26.972830193Z 53 PC: 13888 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:26.974177514Z 37 PC: 13891 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:26.976218478Z 53 PC: 13888 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:26.97769883Z 37 PC: 13891 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:26.979589422Z 53 PC: 13888 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:26.981926302Z 37 PC: 13891 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:26.983918895Z 53 PC: 13888 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:26.985518861Z 37 PC: 13891 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:26.98709382Z 53 PC: 13888 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:26.989215566Z 37 PC: 13891 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:26.990733748Z 53 PC: 13888 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:26.992264814Z 37 PC: 13891 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:26.994259732Z 53 PC: 13888 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:26.995793954Z 37 PC: 13891 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:26.997277041Z 53 PC: 13888 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:26.999551394Z 37 PC: 13891 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:27.001060289Z 53 PC: 13888 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:27.002590223Z 37 PC: 13891 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:27.004854336Z 53 PC: 13888 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:27.006417483Z 37 PC: 13891 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:27.007930616Z 53 PC: 13888 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:27.010249522Z 37 PC: 13891 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:27.012160302Z 53 PC: 13888 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:27.013772731Z 37 PC: 13891 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:27.016750355Z 41 PC: 1383f | Parse filename
2018-12-17T22:50:27.018974444Z 41 PC: 1384d | Parse filename
2018-12-17T22:50:27.020828607Z 75 PC: 13858 | Execute program
2018-12-17T22:50:27.045433191Z 80 PC: 1c209 | Set current PSP
2018-12-17T22:50:27.047132844Z 48 PC: 1c20e | Get DOS version
2018-12-17T22:50:27.049331896Z 99 PC: 229f0 | Get DBCS lead byte table pointer
2018-12-17T22:50:27.052469059Z 101 PC: 1c294 | Get extended country info
2018-12-17T22:50:27.055268358Z 99 PC: 1c29a | Get DBCS lead byte table pointer
2018-12-17T22:50:27.056973441Z 74 PC: 1c2fc | Reallocate memory
2018-12-17T22:50:27.058829228Z 25 PC: 1c333 | Get default drive
2018-12-17T22:50:27.061139878Z 37 PC: 1bdf3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:50:27.062520753Z 37 PC: 1bdfa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:27.063896347Z 37 PC: 1be01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:27.069302975Z 74 PC: 1af9c | Reallocate memory
2018-12-17T22:50:27.071415654Z 72 PC: 1afdd | Allocate memory
2018-12-17T22:50:27.073171893Z 72 PC: 1b015 | Allocate memory
2018-12-17T22:50:27.07522999Z 72 PC: 1b01d | Allocate memory