Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Xep.6099

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:22.3888737Z 53 PC: 138ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:22.390307726Z 53 PC: 138ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:59:22.391237686Z 53 PC: 138ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:22.392230112Z 53 PC: 138ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:22.393987958Z 53 PC: 138ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:22.395004142Z 53 PC: 138ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:22.395944025Z 53 PC: 138ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:59:22.397545495Z 53 PC: 138ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:59:22.398598238Z 53 PC: 138ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:59:22.399595476Z 53 PC: 138ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:59:22.401172166Z 53 PC: 138ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:59:22.402201832Z 53 PC: 138ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:59:22.403283521Z 53 PC: 138ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:59:22.409395016Z 53 PC: 138ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:59:22.410263421Z 53 PC: 138ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:59:22.411105082Z 53 PC: 138ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:59:22.419604778Z 53 PC: 138ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:59:22.42251112Z 53 PC: 138ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:22.423679851Z 53 PC: 138ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:59:22.424878359Z 37 PC: 138ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:22.426869975Z 37 PC: 13907 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:22.428250959Z 37 PC: 1390f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:22.42964313Z 37 PC: 13917 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:22.432388814Z 68 PC: 147dc | I/O control for devices (Set for = ' s=')
2018-12-17T21:59:22.475680755Z 37 PC: 13291 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:22.477132687Z 60 PC: 14213 | Create or truncate file
2018-12-17T21:59:22.495238614Z 65 PC: 1435c | Delete file (Filename = '\xep')
2018-12-17T21:59:22.52410361Z 26 PC: 13835 | Set disk transfer address
2018-12-17T21:59:22.525581606Z 78 PC: 13841 | Find first file
2018-12-17T21:59:22.532572497Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.533687214Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.536995065Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.538736932Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.542401686Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.543872933Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.559483996Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.560621035Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.563939579Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.565804804Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.568632192Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.570136125Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.574049878Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.57526297Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.578589556Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.580416354Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.584021272Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.58539663Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.589910041Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.590963536Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.594191622Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.595720435Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.600337665Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.602290053Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.607580363Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.608606954Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.611838765Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.613354831Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.616694736Z 26 PC: 13859 | Set disk transfer address
2018-12-17T21:59:22.617723911Z 79 PC: 1385e | Find next file
2018-12-17T21:59:22.62141653Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:22.622685441Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:59:22.623823469Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:22.625830857Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:22.627137444Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:22.628252157Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:22.629480953Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:59:22.630818976Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:59:22.631823729Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:59:22.632972271Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:59:22.634447049Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:59:22.635589208Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:59:22.637047464Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:59:22.638360383Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:59:22.639333572Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:59:22.640486501Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:59:22.641901368Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:59:22.643009727Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:22.644127677Z 37 PC: 13a41 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:59:22.645798566Z 76 PC: 13a80 | Terminate with return code (Return code = '0')