Sample viewer

vx.netlux.org/Virus.DOS.HLLP.8112

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:00.842245603Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:00.844477442Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:00.845727131Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:00.853394961Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:00.854985125Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:00.856313472Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:00.858006327Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:00.859975802Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:00.861248623Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:00.862599884Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:00.863789014Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:00.865244344Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:00.866266826Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:00.867262394Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:00.868712616Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:00.869718788Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:00.870700678Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:00.87218603Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:00.873296168Z 53 PC: 139e2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:00.874341031Z 37 PC: 139f7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:00.880257933Z 37 PC: 139ff | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:00.881351553Z 37 PC: 13a07 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:00.882457191Z 37 PC: 13a0f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:00.884523778Z 68 PC: 13d7f | I/O control for devices (Set for = '')
2018-12-17T22:51:00.941581398Z 37 PC: 13195 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:00.943347752Z 48 PC: 14687 | Get DOS version
2018-12-17T22:51:00.94600406Z 25 PC: 14714 | Get default drive
2018-12-17T22:51:00.947020196Z 71 PC: 14727 | Get current directory
2018-12-17T22:51:00.950115008Z 26 PC: 13787 | Set disk transfer address
2018-12-17T22:51:00.95155372Z 78 PC: 13793 | Find first file
2018-12-17T22:51:00.957878649Z 67 PC: 13756 | Get or set file attributes
2018-12-17T22:51:00.974076929Z 61 PC: 14447 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:51:00.980702372Z 66 PC: 14579 | Move file pointer
2018-12-17T22:51:00.982185991Z 63 PC: 144d9 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:51:00.98856628Z 63 PC: 144d9 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:51:00.990986207Z 63 PC: 144d9 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:51:00.993739704Z 62 PC: 14497 | Close file
2018-12-17T22:51:00.995424621Z 26 PC: 137ab | Set disk transfer address
2018-12-17T22:51:00.996406745Z 79 PC: 137b0 | Find next file
2018-12-17T22:51:00.999428733Z 14 PC: 1476d | Set default drive (Drive = 'C')
2018-12-17T22:51:01.000806Z 25 PC: 14771 | Get default drive
2018-12-17T22:51:01.002167049Z 59 PC: 147db | Change current directory
2018-12-17T22:51:01.008745196Z 26 PC: 13787 | Set disk transfer address
2018-12-17T22:51:01.0098616Z 78 PC: 13793 | Find first file
2018-12-17T22:51:01.018398684Z 67 PC: 13756 | Get or set file attributes
2018-12-17T22:51:01.361735035Z 61 PC: 14447 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:51:01.369763214Z 66 PC: 14579 | Move file pointer
2018-12-17T22:51:01.371625519Z 63 PC: 144d9 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:51:01.383430992Z 62 PC: 14497 | Close file
2018-12-17T22:51:01.38550661Z 61 PC: 14447 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:01.392347038Z 60 PC: 14447 | Create or truncate file
2018-12-17T22:51:01.404347135Z 63 PC: 1451a | Read file or device (Read 8112 bytes on handle 5)
2018-12-17T22:51:01.412307357Z 64 PC: 1451a | Write file or device (Write 8112 bytes on handle 6)
2018-12-17T22:51:01.42291961Z 62 PC: 14497 | Close file
2018-12-17T22:51:01.426133174Z 67 PC: 13756 | Get or set file attributes
2018-12-17T22:51:01.43738204Z 61 PC: 14447 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:51:01.444257253Z 66 PC: 145e3 | Move file pointer
2018-12-17T22:51:01.446596802Z 66 PC: 145f1 | Move file pointer
2018-12-17T22:51:01.44828081Z 66 PC: 145ff | Move file pointer
2018-12-17T22:51:01.449983942Z 66 PC: 14579 | Move file pointer
2018-12-17T22:51:01.45231731Z 63 PC: 1451a | Read file or device (Read 8112 bytes on handle 5)
2018-12-17T22:51:01.460114801Z 64 PC: 1451a | Write file or device (Write 8112 bytes on handle 6)
2018-12-17T22:51:01.473014533Z 63 PC: 1451a | Read file or device (Read 8112 bytes on handle 5)
2018-12-17T22:51:01.481134825Z 64 PC: 1451a | Write file or device (Write 3096 bytes on handle 6)
2018-12-17T22:51:01.492340896Z 63 PC: 1451a | Read file or device (Read 8112 bytes on handle 5)
2018-12-17T22:51:01.494474551Z 62 PC: 14497 | Close file
2018-12-17T22:51:01.503650963Z 62 PC: 14497 | Close file
2018-12-17T22:51:01.505920805Z 65 PC: 1461c | Delete file (Filename = 'ATTRIB.EXE')
2018-12-17T22:51:01.516560044Z 86 PC: 14652 | Rename file
2018-12-17T22:51:01.528115713Z 61 PC: 14447 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:01.535901548Z 66 PC: 14579 | Move file pointer
2018-12-17T22:51:01.537754639Z 60 PC: 14447 | Create or truncate file
2018-12-17T22:51:01.548798379Z 63 PC: 1451a | Read file or device (Read 8112 bytes on handle 5)
2018-12-17T22:51:01.557120289Z 64 PC: 1451a | Write file or device (Write 1000 bytes on handle 6)
2018-12-17T22:51:01.565378091Z 63 PC: 1451a | Read file or device (Read 8112 bytes on handle 5)
2018-12-17T22:51:01.567663961Z 62 PC: 14497 | Close file
2018-12-17T22:51:01.570361334Z 66 PC: 145e3 | Move file pointer
2018-12-17T22:51:01.572028639Z 66 PC: 145f1 | Move file pointer
2018-12-17T22:51:01.573712071Z 66 PC: 145ff | Move file pointer
2018-12-17T22:51:01.576006297Z 62 PC: 14497 | Close file
2018-12-17T22:51:01.584017429Z 41 PC: 13883 | Parse filename
2018-12-17T22:51:01.585686011Z 41 PC: 13891 | Parse filename
2018-12-17T22:51:01.587816145Z 75 PC: 1389c | Execute program
2018-12-17T22:51:01.607907413Z 80 PC: 18f99 | Set current PSP
2018-12-17T22:51:01.608923578Z 48 PC: 18f9e | Get DOS version
2018-12-17T22:51:01.611254309Z 99 PC: 1f780 | Get DBCS lead byte table pointer
2018-12-17T22:51:01.614028249Z 101 PC: 19024 | Get extended country info
2018-12-17T22:51:01.615453687Z 99 PC: 1902a | Get DBCS lead byte table pointer
2018-12-17T22:51:01.617513282Z 74 PC: 1908c | Reallocate memory
2018-12-17T22:51:01.619007326Z 25 PC: 190c3 | Get default drive
2018-12-17T22:51:01.620327247Z 37 PC: 18b83 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:51:01.622003267Z 37 PC: 18b8a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:01.623500574Z 37 PC: 18b91 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:01.627805666Z 74 PC: 17d2c | Reallocate memory
2018-12-17T22:51:01.629819007Z 72 PC: 17d6d | Allocate memory
2018-12-17T22:51:01.631429213Z 72 PC: 17da5 | Allocate memory
2018-12-17T22:51:01.632974623Z 72 PC: 17dad | Allocate memory