Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5515

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:19.765293511Z 53 PC: 1395a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:19.767641193Z 53 PC: 1395a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:19.768903729Z 53 PC: 1395a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:19.770496188Z 53 PC: 1395a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:19.773295695Z 53 PC: 1395a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:19.774593646Z 53 PC: 1395a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:19.776030459Z 53 PC: 1395a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:19.777756391Z 53 PC: 1395a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:19.780405161Z 53 PC: 1395a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:19.781644659Z 53 PC: 1395a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:19.782995894Z 53 PC: 1395a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:19.785292856Z 53 PC: 1395a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:19.786724395Z 53 PC: 1395a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:19.788219069Z 53 PC: 1395a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:19.790341079Z 53 PC: 1395a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:19.791912379Z 53 PC: 1395a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:19.793529552Z 53 PC: 1395a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:19.795946344Z 53 PC: 1395a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:19.797449311Z 53 PC: 1395a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:19.799024523Z 37 PC: 1396f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:19.801096457Z 37 PC: 13977 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:19.802360125Z 37 PC: 1397f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:19.803564634Z 37 PC: 13987 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:19.806312746Z 68 PC: 14631 | I/O control for devices (Set for = '')
2018-12-17T22:53:19.807889428Z 53 PC: 13730 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:19.80913796Z 37 PC: 1374c | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:19.811001801Z 48 PC: 14242 | Get DOS version
2018-12-17T22:53:19.813217748Z 61 PC: 14080 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:19.819965121Z 63 PC: 14153 | Read file or device (Read 5515 bytes on handle 5)
2018-12-17T22:53:19.827909113Z 62 PC: 140d0 | Close file
2018-12-17T22:53:19.831252166Z 67 PC: 1377d | Get or set file attributes
2018-12-17T22:53:19.837574458Z 67 PC: 1377d | Get or set file attributes
2018-12-17T22:53:19.847790471Z 67 PC: 1377d | Get or set file attributes
2018-12-17T22:53:19.854473601Z 67 PC: 1377d | Get or set file attributes
2018-12-17T22:53:19.861783359Z 67 PC: 1377d | Get or set file attributes
2018-12-17T22:53:19.868881728Z 67 PC: 1377d | Get or set file attributes
2018-12-17T22:53:19.876182795Z 26 PC: 136cf | Set disk transfer address
2018-12-17T22:53:19.877686565Z 78 PC: 136db | Find first file
2018-12-17T22:53:19.884734173Z 67 PC: 13658 | Get or set file attributes
2018-12-17T22:53:20.228693148Z 61 PC: 14080 | Open file (Filename = 'C:\DOS\mem.exe')
2018-12-17T22:53:20.23645174Z 63 PC: 14153 | Read file or device (Read 5515 bytes on handle 5)
2018-12-17T22:53:20.244507465Z 67 PC: 13658 | Get or set file attributes
2018-12-17T22:53:20.255764063Z 87 PC: 1369f | Get or set file date and time
2018-12-17T22:53:20.257943701Z 62 PC: 140d0 | Close file
2018-12-17T22:53:20.265434005Z 67 PC: 13658 | Get or set file attributes
2018-12-17T22:53:20.275854669Z 61 PC: 14080 | Open file (Filename = 'C:\DOS\mem.exe')
2018-12-17T22:53:20.283241425Z 60 PC: 14080 | Create or truncate file
2018-12-17T22:53:20.301877475Z 64 PC: 14153 | Write file or device (Write 5515 bytes on handle 6)
2018-12-17T22:53:20.311962261Z 66 PC: 147d2 | Move file pointer
2018-12-17T22:53:20.313968163Z 66 PC: 147e0 | Move file pointer
2018-12-17T22:53:20.315887597Z 66 PC: 147ee | Move file pointer
2018-12-17T22:53:20.319371186Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.32624486Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.335676372Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.34337311Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.353243033Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.372467817Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.383080564Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.389893089Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.39928444Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.406785525Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.416160269Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.423057621Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.43331905Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.440101677Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.449428481Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.45667944Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.466438281Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.47326645Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.483540492Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.491063623Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.500467991Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.507523564Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.517697983Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.524472582Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.533978091Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.541706924Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.551708851Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.55852034Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.568999507Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.575856778Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.585276766Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.592872995Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.602303571Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.609175186Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.620149735Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.630702317Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.640269393Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.648057852Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.658076448Z 63 PC: 14153 | Read file or device (Read 1600 bytes on handle 5)
2018-12-17T22:53:20.665040465Z 64 PC: 14153 | Write file or device (Write 1600 bytes on handle 6)
2018-12-17T22:53:20.675873386Z 63 PC: 14153 | Read file or device (Read 502 bytes on handle 5)
2018-12-17T22:53:20.68227009Z 64 PC: 14153 | Write file or device (Write 502 bytes on handle 6)
2018-12-17T22:53:20.690928786Z 67 PC: 13658 | Get or set file attributes
2018-12-17T22:53:20.702952601Z 87 PC: 1369f | Get or set file date and time
2018-12-17T22:53:20.705219811Z 62 PC: 140d0 | Close file
2018-12-17T22:53:20.707025738Z 62 PC: 140d0 | Close file
2018-12-17T22:53:20.71469961Z 65 PC: 141c9 | Delete file (Filename = 'C:\DOS\mem.exe')
2018-12-17T22:53:20.725552613Z 86 PC: 1420d | Rename file
2018-12-17T22:53:20.731339665Z 64 PC: 13fdb | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:53:20.733682802Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:20.735323228Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:20.73644727Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:20.737796316Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:20.739380399Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:20.740472984Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:20.741583855Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:20.743977698Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:20.745040448Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:20.746578732Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:20.748416046Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:20.749826653Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:20.751198791Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:20.753480746Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:20.754569511Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:20.755615999Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:20.758291794Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:20.760083767Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:20.762195104Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:20.76471016Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.768141047Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.770635227Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.773675916Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.776106798Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.778410567Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.781491354Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.783796375Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.786072173Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.789551041Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.795266841Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.797612801Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.800712282Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.803649626Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.8058069Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.808618761Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.811006851Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.813408573Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.816484816Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.819034706Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.821304337Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.824325811Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.826870061Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.829850346Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.83355597Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.836608791Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.838914975Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.841181224Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.844405849Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.846653926Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.848940185Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.85225197Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.854430312Z 6 PC: 13b38 | Direct console I/O
2018-12-17T22:53:20.857946691Z 76 PC: 13af0 | Terminate with return code (Return code = '17')