Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Mouse.6688

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:45.850381265Z 53 PC: 1362e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:45.853268258Z 53 PC: 1362e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:45.855197244Z 53 PC: 1362e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:45.856702317Z 53 PC: 1362e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:45.863132066Z 53 PC: 1362e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:45.865023517Z 53 PC: 1362e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:45.866839232Z 53 PC: 1362e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:45.869010246Z 53 PC: 1362e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:45.870976397Z 53 PC: 1362e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:45.873084784Z 53 PC: 1362e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:45.875262797Z 53 PC: 1362e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:45.876518916Z 53 PC: 1362e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:45.87847417Z 53 PC: 1362e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:45.879962347Z 53 PC: 1362e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:45.881446782Z 53 PC: 1362e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:45.883820017Z 53 PC: 1362e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:45.885229298Z 53 PC: 1362e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:45.88662657Z 53 PC: 1362e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:45.888561635Z 53 PC: 1362e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:45.890079169Z 37 PC: 13643 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:45.89214851Z 37 PC: 1364a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:45.905334361Z 37 PC: 13651 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:45.906568414Z 37 PC: 13658 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:45.908133365Z 68 PC: 13af9 | I/O control for devices (Set for = '�tD���')
2018-12-17T22:53:45.910919693Z 25 PC: 1410d | Get default drive
2018-12-17T22:53:45.912293913Z 71 PC: 14120 | Get current directory
2018-12-17T22:53:45.915625193Z 14 PC: 1416c | Set default drive (Drive = 'C')
2018-12-17T22:53:45.9176716Z 25 PC: 14170 | Get default drive
2018-12-17T22:53:45.919168958Z 59 PC: 141dc | Change current directory
2018-12-17T22:53:45.928016895Z 14 PC: 1416c | Set default drive (Drive = 'A')
2018-12-17T22:53:45.929969746Z 25 PC: 14170 | Get default drive
2018-12-17T22:53:45.9320689Z 59 PC: 141dc | Change current directory
2018-12-17T22:53:45.936520216Z 81 PC: 12daf | Get current PSP
2018-12-17T22:53:45.93863907Z 61 PC: 13ead | Open file (Filename = 'c:\windows\mouse.exe')
2018-12-17T22:53:45.950405103Z 41 PC: 134cd | Parse filename
2018-12-17T22:53:45.951909814Z 41 PC: 134db | Parse filename
2018-12-17T22:53:45.953738668Z 75 PC: 134e6 | Execute program
2018-12-17T22:53:45.974694866Z 80 PC: 16839 | Set current PSP
2018-12-17T22:53:45.975871385Z 48 PC: 1683e | Get DOS version
2018-12-17T22:53:45.977595216Z 99 PC: 1d020 | Get DBCS lead byte table pointer
2018-12-17T22:53:45.980787999Z 101 PC: 168c4 | Get extended country info
2018-12-17T22:53:45.982089084Z 99 PC: 168ca | Get DBCS lead byte table pointer
2018-12-17T22:53:45.983348727Z 74 PC: 1692c | Reallocate memory
2018-12-17T22:53:45.985888801Z 25 PC: 16963 | Get default drive
2018-12-17T22:53:45.987025199Z 37 PC: 16423 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:53:45.988152976Z 37 PC: 1642a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:45.990167485Z 37 PC: 16431 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:45.994477695Z 74 PC: 155cc | Reallocate memory
2018-12-17T22:53:45.996091593Z 72 PC: 1560d | Allocate memory
2018-12-17T22:53:45.998776896Z 72 PC: 15645 | Allocate memory
2018-12-17T22:53:46.000704032Z 72 PC: 1564d | Allocate memory