Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Pepe.6810.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:16.013936956Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.016075835Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:16.017681296Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:16.018904246Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:16.028277593Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.029952492Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.031000458Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:16.032286746Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:16.033642717Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:16.034930518Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:16.036049758Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:16.0378831Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:16.03935721Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:16.040510024Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:16.042073396Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:16.042924961Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:16.043750818Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:16.045828346Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.047016896Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:16.048592534Z 37 PC: 13f1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.050530307Z 37 PC: 13f27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.051699692Z 37 PC: 13f2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.052632803Z 37 PC: 13f37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.054621796Z 68 PC: 14be1 | I/O control for devices (Set for = '�')
2018-12-17T21:51:16.056456517Z 44 PC: 14d18 | Get time 0x14d18: mov word ptr [0x8a], cx
0x14d1c: mov word ptr [0x8c], dx
0x14d20: retf
0x14d21: call 0x14d68
0x14d24: jb 0x14d35
0x14d26: mov cx, word ptr es:[di + 4]
0x14d2a: cmp cx, 1
0x14d2d: je 0x14d35
0x14d2f: xor bx, bx
0x14d31: push cs
0x14d32: call 0x248a4
0x14d35: retf 4
0x14d38: call 0x14d68
0x14d3b: jb 0x14d50
0x14d3d: mov ax, cx
0x14d3f: mov dx, bx
0x14d41: mov cx, word ptr es:[di + 4]
0x14d45: cmp cx, 1
0x14d48: je 0x14d50
0x14d4a: xor bx, bx
2018-12-17T21:51:16.059058654Z 48 PC: 147f2 | Get DOS version
2018-12-17T21:51:16.060768296Z 67 PC: 13cdf | Get or set file attributes
2018-12-17T21:51:16.066835594Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T21:51:16.083285714Z 61 PC: 14630 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:16.090042391Z 63 PC: 14703 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T21:51:16.096428854Z 66 PC: 14762 | Move file pointer
2018-12-17T21:51:16.097891547Z 63 PC: 14703 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T21:51:16.101382286Z 63 PC: 14703 | Read file or device (Read 6810 bytes on handle 5)
2018-12-17T21:51:16.10394904Z 60 PC: 14630 | Create or truncate file
2018-12-17T21:51:16.115685424Z 63 PC: 14703 | Read file or device (Read 10000 bytes on handle 5)
2018-12-17T21:51:16.119179383Z 66 PC: 14d82 | Move file pointer
2018-12-17T21:51:16.120943847Z 66 PC: 14d90 | Move file pointer
2018-12-17T21:51:16.122609421Z 66 PC: 14d9e | Move file pointer
2018-12-17T21:51:16.124903601Z 62 PC: 14680 | Close file
2018-12-17T21:51:16.127008227Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T21:51:16.137001427Z 62 PC: 14680 | Close file
2018-12-17T21:51:16.141521119Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.143037462Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.144273709Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:16.148349149Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:16.149556569Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:16.150825875Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:16.15395555Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:16.155145293Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:16.156198532Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.157931249Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.158908559Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.159887592Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.161430402Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:16.16251029Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:16.163465382Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:16.165093597Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:16.166855681Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:16.168190975Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:16.17426199Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:16.17561761Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:16.177307473Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:16.180491402Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:16.18180804Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:16.183188613Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:16.185454407Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:16.186843924Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:16.18817648Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:16.190463198Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:16.191878286Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:16.193643618Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:16.194952206Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:16.197103151Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:16.198265312Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:16.199726603Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:16.201561387Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.203913233Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.211574483Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:16.213981105Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:16.215650054Z 41 PC: 13e35 | Parse filename
2018-12-17T21:51:16.217474273Z 41 PC: 13e43 | Parse filename
2018-12-17T21:51:16.218958803Z 75 PC: 13e4e | Execute program
2018-12-17T21:51:16.227659886Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.229369593Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.234861969Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:16.236512079Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:16.241130019Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:16.244641146Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:16.24649206Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:16.247717396Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:16.250965474Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.25288487Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.254305383Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.257175241Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.25845499Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:16.259839159Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:16.261889832Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:16.263189008Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:16.264475078Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:16.266927317Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:16.268141032Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:16.26939523Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:16.271191689Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:16.272616572Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:16.27399376Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:16.275933918Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:16.276974896Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:16.278236577Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:16.28647061Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:16.287898252Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:16.289504528Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:16.29116915Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:16.292286884Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:16.293697211Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:16.295645095Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:16.296830975Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:16.297907374Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.299629731Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.300625106Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:16.301903958Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:16.304045603Z 65 PC: 14779 | Delete file (Filename = 'Victim.Exe')
2018-12-17T21:51:16.319994346Z 26 PC: 13d7d | Set disk transfer address
2018-12-17T21:51:16.320993284Z 78 PC: 13d89 | Find first file
2018-12-17T21:51:16.327421588Z 86 PC: 147bd | Rename file
2018-12-17T21:51:16.339020246Z 60 PC: 14630 | Create or truncate file
2018-12-17T21:51:16.349597544Z 67 PC: 13cdf | Get or set file attributes
2018-12-17T21:51:16.355713427Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T21:51:16.365197983Z 61 PC: 14630 | Open file (Filename = 'Victim.Exe')
2018-12-17T21:51:16.371633556Z 64 PC: 14703 | Write file or device (Write 4852 bytes on handle 5)
2018-12-17T21:51:16.380051234Z 64 PC: 14703 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T21:51:16.382688606Z 64 PC: 14703 | Write file or device (Write 6810 bytes on handle 5)
2018-12-17T21:51:16.39285055Z 63 PC: 14703 | Read file or device (Read 10000 bytes on handle 6)
2018-12-17T21:51:16.401412506Z 64 PC: 14703 | Write file or device (Write 9744 bytes on handle 5)
2018-12-17T21:51:16.410144521Z 66 PC: 14d82 | Move file pointer
2018-12-17T21:51:16.411554411Z 66 PC: 14d90 | Move file pointer
2018-12-17T21:51:16.414134926Z 66 PC: 14d9e | Move file pointer
2018-12-17T21:51:16.415503452Z 87 PC: 13d4d | Get or set file date and time
2018-12-17T21:51:16.416968625Z 62 PC: 14680 | Close file
2018-12-17T21:51:16.419712575Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T21:51:16.429969237Z 62 PC: 14680 | Close file
2018-12-17T21:51:16.437296676Z 65 PC: 14779 | Delete file (Filename = 'Victim.Exe')
2018-12-17T21:51:16.449153146Z 26 PC: 13da1 | Set disk transfer address
2018-12-17T21:51:16.450660687Z 79 PC: 13da6 | Find next file
2018-12-17T21:51:16.453367347Z 26 PC: 13da1 | Set disk transfer address
2018-12-17T21:51:16.45816488Z 79 PC: 13da6 | Find next file
2018-12-17T21:51:16.461904666Z 64 PC: 1458b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:51:16.463235264Z 37 PC: 14061 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:16.465260528Z 37 PC: 14061 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:16.466498332Z 37 PC: 14061 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:16.467521894Z 37 PC: 14061 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:16.469120839Z 37 PC: 14061 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:16.470231215Z 37 PC: 14061 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:16.471225837Z 37 PC: 14061 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:16.473071Z 37 PC: 14061 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:16.4745584Z 37 PC: 14061 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:16.476067786Z 37 PC: 14061 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:16.478340096Z 37 PC: 14061 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:16.479827211Z 37 PC: 14061 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:16.481289295Z 37 PC: 14061 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:16.483193551Z 37 PC: 14061 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:16.48465673Z 37 PC: 14061 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:16.48616194Z 37 PC: 14061 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:16.487945901Z 37 PC: 14061 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:16.489359524Z 37 PC: 14061 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:16.490705214Z 37 PC: 14061 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:16.492695069Z 76 PC: 140a0 | Terminate with return code (Return code = '0')