Sample viewer

vx.netlux.org/Virus.DOS.HLLW.Tron.4459

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:38.081659329Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:38.083574467Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:38.085257469Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:38.086730587Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:38.088189367Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:38.0906819Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:38.092165888Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:38.093711081Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:38.096304363Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:38.098350386Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:38.100333682Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:38.104336172Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:38.106342531Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:38.108126102Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:38.110724373Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:38.113018342Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:38.114741329Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:38.116342107Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:38.118344849Z 53 PC: 12e7a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:38.119700867Z 37 PC: 12e8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:38.120977836Z 37 PC: 12e97 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:38.1231411Z 37 PC: 12e9f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:38.125349198Z 37 PC: 12ea7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:38.127927983Z 68 PC: 13d8a | I/O control for devices (Set for = '�r �S�@t3��O�:���II �x ����ø`��w���@')
2018-12-17T22:50:38.131082779Z 48 PC: 1399b | Get DOS version
2018-12-17T22:50:38.132726508Z 61 PC: 137d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:50:38.140764568Z 66 PC: 13e89 | Move file pointer
2018-12-17T22:50:38.143713268Z 66 PC: 13e97 | Move file pointer
2018-12-17T22:50:38.145150568Z 66 PC: 13ea5 | Move file pointer
2018-12-17T22:50:38.146969154Z 63 PC: 138ac | Read file or device (Read 4459 bytes on handle 5)
2018-12-17T22:50:38.156243418Z 62 PC: 13829 | Close file
2018-12-17T22:50:38.159125152Z 60 PC: 137d9 | Create or truncate file
2018-12-17T22:50:38.178160933Z 64 PC: 138ac | Write file or device (Write 4459 bytes on handle 5)
2018-12-17T22:50:38.189551783Z 62 PC: 13829 | Close file
2018-12-17T22:50:38.199124437Z 26 PC: 12c85 | Set disk transfer address
2018-12-17T22:50:38.2004249Z 78 PC: 12c91 | Find first file
2018-12-17T22:50:38.21067722Z 65 PC: 13922 | Delete file (Filename = 'setup1.exe')
2018-12-17T22:50:38.225339185Z 64 PC: 134a0 | Write file or device (Write 24 bytes on handle 1)
2018-12-17T22:50:38.230715235Z 64 PC: 134a0 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:50:38.235934741Z 64 PC: 134a0 | Write file or device (Write 59 bytes on handle 1)
2018-12-17T22:50:38.243607395Z 64 PC: 134a0 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:50:38.245999309Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:38.247722766Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:38.250712864Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:38.252581013Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:38.254982926Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:38.257956752Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:38.259494632Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:38.261016401Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:38.262795633Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:38.265047954Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:38.266528706Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:38.267985713Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:38.270555391Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:38.272076298Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:38.273567359Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:38.276251572Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:38.277689153Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:38.279029802Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:38.281480085Z 37 PC: 12fd1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:38.283366879Z 76 PC: 13010 | Terminate with return code (Return code = '0')