Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DH.7199

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:17.789805002Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:17.797458258Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:59:17.799038719Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:17.800419068Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:17.802863999Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:17.804257391Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:17.80565575Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:59:17.807939495Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:59:17.809025727Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:59:17.810046463Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:59:17.813025035Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:59:17.814591572Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:59:17.81600854Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:59:17.819813798Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:59:17.823295266Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:59:17.82433871Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:59:17.826279542Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:59:17.827492718Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:17.828396048Z 53 PC: 13cfa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:59:17.830312691Z 37 PC: 13d0f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:17.832013029Z 37 PC: 13d17 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:17.833498083Z 37 PC: 13d1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:17.836127859Z 37 PC: 13d27 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:17.837961823Z 68 PC: 14ab7 | I/O control for devices (Set for = '?')
2018-12-17T21:59:17.859079323Z 37 PC: 133c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:17.861658601Z 44 PC: 14bee | Get time 0x14bee: mov word ptr [0x56], cx
0x14bf2: mov word ptr [0x58], dx
0x14bf6: retf
0x14bf7: call 0x14c3e
0x14bfa: jb 0x14c0b
0x14bfc: mov cx, word ptr es:[di + 4]
0x14c00: cmp cx, 1
0x14c03: je 0x14c0b
0x14c05: xor bx, bx
0x14c07: push cs
0x14c08: call 0x2477a
0x14c0b: retf 4
0x14c0e: call 0x14c3e
0x14c11: jb 0x14c26
0x14c13: mov ax, cx
0x14c15: mov dx, bx
0x14c17: mov cx, word ptr es:[di + 4]
0x14c1b: cmp cx, 1
0x14c1e: je 0x14c26
0x14c20: xor bx, bx
2018-12-17T21:59:17.864044611Z 48 PC: 145e2 | Get DOS version
2018-12-17T21:59:17.865844865Z 61 PC: 14420 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:59:17.873208987Z 63 PC: 144f3 | Read file or device (Read 7195 bytes on handle 5)
2018-12-17T21:59:17.88193881Z 62 PC: 14470 | Close file
2018-12-17T21:59:17.883862609Z 25 PC: 1466f | Get default drive
2018-12-17T21:59:17.885383164Z 71 PC: 14682 | Get current directory
2018-12-17T21:59:17.889490104Z 26 PC: 13b3e | Set disk transfer address
2018-12-17T21:59:17.890622136Z 78 PC: 13a87 | Find first file
2018-12-17T21:59:17.897991303Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:17.904672236Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:17.906367509Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.910546001Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.914356367Z 62 PC: 14470 | Close file
2018-12-17T21:59:17.91657524Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:17.923284007Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:17.925072887Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.927985994Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.931579773Z 62 PC: 14470 | Close file
2018-12-17T21:59:17.933927749Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:17.940560144Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:17.942618021Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.949676422Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.952418021Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.955683826Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:17.958641391Z 62 PC: 14470 | Close file
2018-12-17T21:59:17.960504491Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:17.962128478Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:17.965667001Z 26 PC: 13b3e | Set disk transfer address
2018-12-17T21:59:17.966682738Z 78 PC: 13a87 | Find first file
2018-12-17T21:59:17.972813851Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:17.973833474Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:17.976246367Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:17.978031881Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:17.98051896Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:17.981562103Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:17.985244166Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:17.986463493Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:17.996549044Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:17.999831524Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.002301531Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.003701865Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.006800835Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.007950336Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.010727764Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.012797657Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.015783339Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.017126481Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.020723502Z 59 PC: 14736 | Change current directory
2018-12-17T21:59:18.025132575Z 26 PC: 13b3e | Set disk transfer address
2018-12-17T21:59:18.026195563Z 78 PC: 13a87 | Find first file
2018-12-17T21:59:18.032536181Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:18.039653112Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.041236927Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.044406943Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.047963802Z 62 PC: 14470 | Close file
2018-12-17T21:59:18.050703643Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:18.057744733Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.060535472Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.063701974Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.067612734Z 62 PC: 14470 | Close file
2018-12-17T21:59:18.070832697Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:18.078551877Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.080007242Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.084560573Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.08737811Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.093817059Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.098146042Z 62 PC: 14470 | Close file
2018-12-17T21:59:18.100292176Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.10270891Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.107245272Z 26 PC: 13b3e | Set disk transfer address
2018-12-17T21:59:18.108728229Z 78 PC: 13a87 | Find first file
2018-12-17T21:59:18.11493245Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.117278605Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.12057784Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.121947995Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.125234763Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.126869083Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.129659938Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.131835827Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.134664467Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.13602989Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.13967132Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.141448979Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.144210648Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.146346812Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.15005715Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.151323606Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.154604989Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.156515883Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.159568603Z 59 PC: 14736 | Change current directory
2018-12-17T21:59:18.164390363Z 26 PC: 13b3e | Set disk transfer address
2018-12-17T21:59:18.165507145Z 78 PC: 13a87 | Find first file
2018-12-17T21:59:18.171765937Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:18.178977929Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.180546972Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.183868927Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.187536306Z 62 PC: 14470 | Close file
2018-12-17T21:59:18.190016546Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:18.196819033Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.199191885Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.202378073Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.205179581Z 62 PC: 14470 | Close file
2018-12-17T21:59:18.208453363Z 61 PC: 14420 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:18.215269185Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.21682007Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.221951656Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.22533094Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.228240711Z 63 PC: 144b2 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:59:18.232395613Z 62 PC: 14470 | Close file
2018-12-17T21:59:18.234346177Z 26 PC: 13b60 | Set disk transfer address
2018-12-17T21:59:18.23562927Z 79 PC: 13b65 | Find next file
2018-12-17T21:59:18.240411746Z 14 PC: 146c8 | Set default drive (Drive = 'A')
2018-12-17T21:59:18.242116032Z 25 PC: 146cc | Get default drive
2018-12-17T21:59:18.243575934Z 59 PC: 14736 | Change current directory
2018-12-17T21:59:18.248700871Z 48 PC: 145e2 | Get DOS version
2018-12-17T21:59:18.25084785Z 61 PC: 14420 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:59:18.257663257Z 66 PC: 14c58 | Move file pointer
2018-12-17T21:59:18.260098496Z 66 PC: 14c66 | Move file pointer
2018-12-17T21:59:18.262124487Z 66 PC: 14c74 | Move file pointer
2018-12-17T21:59:18.263868183Z 66 PC: 14552 | Move file pointer
2018-12-17T21:59:18.266595507Z 63 PC: 144f3 | Read file or device (Read 7195 bytes on handle 5)