Sample viewer

vx.netlux.org/Virus.DOS.HLLP.PPZ.7864

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:45.475378727Z 53 PC: 149aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:45.480943471Z 53 PC: 149aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:45.487393168Z 53 PC: 149aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:45.490039957Z 53 PC: 149aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:45.495894437Z 53 PC: 149aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:45.498538255Z 53 PC: 149aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:45.50050452Z 53 PC: 149aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:45.503273757Z 53 PC: 149aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:45.515958657Z 53 PC: 149aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:45.51819672Z 53 PC: 149aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:45.519849595Z 53 PC: 149aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:45.521742609Z 53 PC: 149aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:45.523376651Z 53 PC: 149aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:45.524987666Z 53 PC: 149aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:45.52690795Z 53 PC: 149aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:45.528188278Z 53 PC: 149aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:45.529438563Z 53 PC: 149aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:45.531357765Z 53 PC: 149aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:45.532949487Z 53 PC: 149aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:45.534633451Z 37 PC: 149bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:45.53717722Z 37 PC: 149c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:45.538569632Z 37 PC: 149cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:45.540002967Z 37 PC: 149d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:45.543037109Z 68 PC: 1550c | I/O control for devices (Set for = '')
2018-12-17T22:50:45.630054956Z 37 PC: 140c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:45.632058509Z 48 PC: 15232 | Get DOS version
2018-12-17T22:50:45.634000296Z 53 PC: 147e1 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:50:45.635990536Z 37 PC: 147fd | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:50:45.637907685Z 53 PC: 147e1 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:50:45.63948639Z 37 PC: 147fd | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:50:45.642345565Z 53 PC: 147e1 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:45.644226591Z 37 PC: 147fd | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:45.645724018Z 51 PC: 146cf | Get or set Ctrl-Break
2018-12-17T22:50:45.655841858Z 60 PC: 15070 | Create or truncate file
2018-12-17T22:50:45.675797778Z 65 PC: 151b9 | Delete file (Filename = '/�')
2018-12-17T22:50:45.688417694Z 48 PC: 15232 | Get DOS version
2018-12-17T22:50:45.691398965Z 61 PC: 15070 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:50:45.700429328Z 66 PC: 151a2 | Move file pointer
2018-12-17T22:50:45.702824242Z 63 PC: 15143 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:50:45.712184015Z 62 PC: 150c0 | Close file
2018-12-17T22:50:45.719380997Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:45.720593761Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:45.721792616Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:45.723400914Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:45.724704375Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:45.726672033Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:45.729316394Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:45.730698371Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:45.732041972Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:45.734474207Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:45.735876584Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:45.737255669Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:45.739684108Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:45.74096821Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:45.742415084Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:45.744708136Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:45.746035212Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:45.747594016Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:45.749577259Z 37 PC: 14b01 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:45.751882057Z 76 PC: 14b40 | Terminate with return code (Return code = '8')