Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3680

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:11.684637117Z 53 PC: 13232 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:11.68714107Z 53 PC: 13232 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:11.688624968Z 53 PC: 13232 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:11.690149792Z 53 PC: 13232 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:11.697924218Z 53 PC: 13232 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:11.699336751Z 53 PC: 13232 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:11.700733666Z 53 PC: 13232 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:11.704852232Z 53 PC: 13232 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:11.70669283Z 53 PC: 13232 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:11.708645779Z 53 PC: 13232 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:11.710751075Z 53 PC: 13232 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:11.716395408Z 53 PC: 13232 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:11.717982439Z 53 PC: 13232 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:11.720392848Z 53 PC: 13232 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:11.722016618Z 53 PC: 13232 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:11.723925164Z 53 PC: 13232 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:11.730945592Z 53 PC: 13232 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:11.732624576Z 53 PC: 13232 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:11.734237987Z 53 PC: 13232 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:11.736090828Z 37 PC: 13247 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:11.73838071Z 37 PC: 1324f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:11.740105019Z 37 PC: 13257 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:11.741822075Z 37 PC: 1325f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:11.744261267Z 68 PC: 1357c | I/O control for devices (Set for = '')
2018-12-17T22:51:11.746255192Z 48 PC: 13bab | Get DOS version
2018-12-17T22:51:11.748345028Z 61 PC: 139d1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:11.762153068Z 87 PC: 12f6e | Get or set file date and time
2018-12-17T22:51:11.764841919Z 26 PC: 12fcb | Set disk transfer address
2018-12-17T22:51:11.766458296Z 78 PC: 12fd7 | Find first file
2018-12-17T22:51:11.774606834Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.776031941Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.779611686Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.783417816Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.786811843Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.788386471Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.792416772Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.793677199Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.79722821Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.799467347Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.802724356Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.804024358Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.808010917Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.809840504Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.813342473Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.815159256Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.818820514Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.821624401Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.824879196Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.827177764Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.831073833Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.832650114Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.837322442Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.838612625Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.841781979Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.84383721Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.847282683Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.848676852Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.853645166Z 61 PC: 139d1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:11.861481407Z 63 PC: 13aa4 | Read file or device (Read 3680 bytes on handle 6)
2018-12-17T22:51:11.876533163Z 66 PC: 13b6d | Move file pointer
2018-12-17T22:51:11.879308487Z 66 PC: 13b7b | Move file pointer
2018-12-17T22:51:11.880839914Z 66 PC: 13b89 | Move file pointer
2018-12-17T22:51:11.882356032Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.884805363Z 64 PC: 13aa4 | Write file or device (Write 3680 bytes on handle 6)
2018-12-17T22:51:11.902867064Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.90489808Z 63 PC: 13aa4 | Read file or device (Read 3680 bytes on handle 5)
2018-12-17T22:51:11.914484569Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.917276584Z 64 PC: 13aa4 | Write file or device (Write 3680 bytes on handle 6)
2018-12-17T22:51:11.926101923Z 87 PC: 12f9b | Get or set file date and time
2018-12-17T22:51:11.928558959Z 62 PC: 13a21 | Close file
2018-12-17T22:51:11.937777978Z 26 PC: 12fef | Set disk transfer address
2018-12-17T22:51:11.939441854Z 79 PC: 12ff4 | Find next file
2018-12-17T22:51:11.943550843Z 66 PC: 13b6d | Move file pointer
2018-12-17T22:51:11.946203285Z 66 PC: 13b7b | Move file pointer
2018-12-17T22:51:11.94810073Z 66 PC: 13b89 | Move file pointer
2018-12-17T22:51:11.949806444Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.954102075Z 63 PC: 13aa4 | Read file or device (Read 3680 bytes on handle 5)
2018-12-17T22:51:11.9622818Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.96417122Z 63 PC: 13aa4 | Read file or device (Read 3680 bytes on handle 5)
2018-12-17T22:51:11.973798787Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.975721408Z 64 PC: 13aa4 | Write file or device (Write 3680 bytes on handle 5)
2018-12-17T22:51:11.984661634Z 66 PC: 13b03 | Move file pointer
2018-12-17T22:51:11.987536554Z 64 PC: 13aa4 | Write file or device (Write 3680 bytes on handle 5)
2018-12-17T22:51:11.997170203Z 87 PC: 12f9b | Get or set file date and time
2018-12-17T22:51:11.999713761Z 62 PC: 13a21 | Close file
2018-12-17T22:51:12.008621785Z 53 PC: 130ae | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:12.010642161Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:12.012293733Z 53 PC: 130ae | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:12.014366407Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:12.018680672Z 53 PC: 130ae | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:12.020313078Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:12.025580353Z 53 PC: 130ae | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:12.027361009Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:12.028950735Z 53 PC: 130ae | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:12.030977413Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:12.032619978Z 53 PC: 130ae | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:12.033975815Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:12.035519175Z 53 PC: 130ae | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:12.037515124Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:12.038813533Z 53 PC: 130ae | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:12.040367082Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:12.042042699Z 53 PC: 130ae | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:12.043235581Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:12.044953188Z 53 PC: 130ae | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:12.046763579Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:12.048301808Z 53 PC: 130ae | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:12.049886425Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:12.051760235Z 53 PC: 130ae | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:12.053108859Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:12.054391448Z 53 PC: 130ae | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:12.056917643Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:12.058614792Z 53 PC: 130ae | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:12.060252118Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:12.062430561Z 53 PC: 130ae | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:12.063921782Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:12.065364011Z 53 PC: 130ae | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:12.067888454Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:12.069359437Z 53 PC: 130ae | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:12.070895903Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:12.073616965Z 53 PC: 130ae | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:12.075193697Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:12.076742808Z 53 PC: 130ae | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:12.079048549Z 37 PC: 130b7 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:12.080937227Z 41 PC: 13137 | Parse filename
2018-12-17T22:51:12.082797472Z 41 PC: 13145 | Parse filename
2018-12-17T22:51:12.085039303Z 75 PC: 13150 | Execute program