Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Gluk.4357

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:30.083741154Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.085702417Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:30.089487597Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:30.091391041Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:30.093171802Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.095804807Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.09737939Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:30.098804353Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:30.101169006Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:30.103030508Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:30.104965592Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:30.108298835Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:30.115389757Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:30.117078649Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:30.11857987Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:30.124508811Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:30.125665756Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:30.126868101Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.12881051Z 53 PC: 12eaa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:30.13071186Z 37 PC: 12ebf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.132465323Z 37 PC: 12ec7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.13493842Z 37 PC: 12ecf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.137319899Z 37 PC: 12ed7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.139340281Z 68 PC: 13d29 | I/O control for devices (Set for = '�����')
2018-12-17T22:52:30.141900391Z 48 PC: 1393a | Get DOS version
2018-12-17T22:52:30.143895179Z 61 PC: 13778 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:52:30.152029892Z 63 PC: 1384b | Read file or device (Read 4357 bytes on handle 5)
2018-12-17T22:52:30.161334074Z 66 PC: 138aa | Move file pointer
2018-12-17T22:52:30.163559167Z 66 PC: 13e28 | Move file pointer
2018-12-17T22:52:30.165844665Z 66 PC: 13e36 | Move file pointer
2018-12-17T22:52:30.168785971Z 66 PC: 13e44 | Move file pointer
2018-12-17T22:52:30.171763777Z 60 PC: 13778 | Create or truncate file
2018-12-17T22:52:30.191634755Z 66 PC: 138aa | Move file pointer
2018-12-17T22:52:30.193861248Z 63 PC: 1384b | Read file or device (Read 30 bytes on handle 5)
2018-12-17T22:52:30.197747456Z 62 PC: 137c8 | Close file
2018-12-17T22:52:30.200459107Z 62 PC: 137c8 | Close file
2018-12-17T22:52:30.203199295Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.205833581Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.20782132Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:30.209798476Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:30.212298873Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:30.214382612Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:30.216421481Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:30.218925033Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:30.220373868Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.221798955Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.224858492Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.226251036Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.227891392Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:30.230049588Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:30.231890725Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:30.233647493Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:30.235567479Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:30.237762665Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:30.239140257Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:30.240507002Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:30.251848728Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:30.253612156Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:30.255201325Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:30.257139456Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:30.25851077Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:30.259822007Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:30.261729234Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:30.26419063Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:30.265619283Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:30.2679875Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:30.26946436Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:30.270841478Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:30.272345275Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:30.274602541Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:30.275925916Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.277663839Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.279630259Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:30.280942251Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:30.282541499Z 41 PC: 12ddd | Parse filename
2018-12-17T22:52:30.284528359Z 41 PC: 12deb | Parse filename
2018-12-17T22:52:30.286291034Z 75 PC: 12df6 | Execute program
2018-12-17T22:52:30.296436672Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.29893329Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.300501933Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:30.302024908Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:30.304464884Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:30.306007464Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:30.307510552Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:30.309472692Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:30.310762339Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.312225929Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.314033033Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.315092723Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.31613906Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:30.317710926Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:30.318686068Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:30.31985161Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:30.321538058Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:30.322477173Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:30.323502342Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:30.32515102Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:30.326219411Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:30.327347648Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:30.328863002Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:30.330071295Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:30.331160687Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:30.332563344Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:30.333755309Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:30.334740086Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:30.335892456Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:30.337510435Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:30.338951769Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:30.339909746Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:30.341272274Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:30.342824493Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:30.344555702Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.347309858Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.349129767Z 53 PC: 12e26 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:30.351003644Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:30.353688538Z 65 PC: 138c1 | Delete file (Filename = '����u)��')
2018-12-17T22:52:30.366008656Z 26 PC: 12d25 | Set disk transfer address
2018-12-17T22:52:30.36759596Z 78 PC: 12d31 | Find first file
2018-12-17T22:52:30.375538645Z 61 PC: 13778 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:52:30.383850382Z 63 PC: 1384b | Read file or device (Read 30 bytes on handle 5)
2018-12-17T22:52:30.387225388Z 62 PC: 137c8 | Close file
2018-12-17T22:52:30.390240941Z 26 PC: 12d49 | Set disk transfer address
2018-12-17T22:52:30.392145576Z 79 PC: 12d4e | Find next file
2018-12-17T22:52:30.396062025Z 64 PC: 134d0 | Write file or device (Write 19 bytes on handle 1)
2018-12-17T22:52:30.402620368Z 64 PC: 134d0 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:52:30.405308749Z 37 PC: 13001 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:30.407068051Z 37 PC: 13001 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:30.408977451Z 37 PC: 13001 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:30.411547075Z 37 PC: 13001 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:30.413042933Z 37 PC: 13001 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.414961172Z 37 PC: 13001 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.416891056Z 37 PC: 13001 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:30.417821678Z 37 PC: 13001 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:30.419140152Z 37 PC: 13001 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:30.421515065Z 37 PC: 13001 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:30.422609316Z 37 PC: 13001 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:30.423761741Z 37 PC: 13001 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:30.425077432Z 37 PC: 13001 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:30.426100395Z 37 PC: 13001 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:30.427110395Z 37 PC: 13001 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:30.428462288Z 37 PC: 13001 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:30.429442043Z 37 PC: 13001 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:30.430464354Z 37 PC: 13001 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:30.431941519Z 37 PC: 13001 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:30.433087444Z 76 PC: 13040 | Terminate with return code (Return code = '0')