Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Xep.4547

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:56.156691454Z 53 PC: 1350a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:56.160107982Z 53 PC: 1350a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:56.161536025Z 53 PC: 1350a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:56.163035003Z 53 PC: 1350a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:56.171474044Z 53 PC: 1350a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:56.173004244Z 53 PC: 1350a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:56.174463335Z 53 PC: 1350a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:56.17614013Z 53 PC: 1350a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:56.185607789Z 53 PC: 1350a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:56.18698267Z 53 PC: 1350a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:56.188341721Z 53 PC: 1350a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:56.190469857Z 53 PC: 1350a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:56.191864233Z 53 PC: 1350a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:56.193220871Z 53 PC: 1350a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:56.195549414Z 53 PC: 1350a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:56.196889805Z 53 PC: 1350a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:56.198267938Z 53 PC: 1350a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:56.200536778Z 53 PC: 1350a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:56.201898244Z 53 PC: 1350a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:56.204108529Z 37 PC: 1351f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:56.206831867Z 37 PC: 13527 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:56.210538218Z 37 PC: 1352f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:56.21190745Z 37 PC: 13537 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:56.217246938Z 68 PC: 14084 | I/O control for devices (Set for = '��[����')
2018-12-17T22:53:56.218639385Z 48 PC: 13d92 | Get DOS version
2018-12-17T22:53:56.219791076Z 60 PC: 13bd0 | Create or truncate file
2018-12-17T22:53:56.233625563Z 65 PC: 13d19 | Delete file (Filename = '\�')
2018-12-17T22:53:56.240734414Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.243658448Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.247650412Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.255630127Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.259404155Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.262376823Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.266790123Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.273139881Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.276151079Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.280482251Z 64 PC: 13928 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:53:56.283880338Z 26 PC: 13294 | Set disk transfer address
2018-12-17T22:53:56.284803561Z 78 PC: 13287 | Find first file
2018-12-17T22:53:56.289647987Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.290557255Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.29289281Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.294323127Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.296663007Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.297564795Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.300892032Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.30250724Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.305240909Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.306685699Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.308995736Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.309825691Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.312812845Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.313660219Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.316086909Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.317434288Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.31971738Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.320522163Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.323269111Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.324059551Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.326325951Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.32770677Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.330167986Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.331077566Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.333723713Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.334535395Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.336797241Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.338141713Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.340384613Z 26 PC: 132b6 | Set disk transfer address
2018-12-17T22:53:56.341203726Z 79 PC: 132bb | Find next file
2018-12-17T22:53:56.343994104Z 64 PC: 13928 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:53:56.345651489Z 37 PC: 13661 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:56.346998819Z 37 PC: 13661 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:56.349633508Z 37 PC: 13661 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:56.350985469Z 37 PC: 13661 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:56.352230648Z 37 PC: 13661 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:56.354336297Z 37 PC: 13661 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:56.355179535Z 37 PC: 13661 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:56.355959834Z 37 PC: 13661 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:56.357458687Z 37 PC: 13661 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:56.358304394Z 37 PC: 13661 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:56.359053128Z 37 PC: 13661 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:56.360271442Z 37 PC: 13661 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:56.361251368Z 37 PC: 13661 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:56.362003654Z 37 PC: 13661 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:56.363379286Z 37 PC: 13661 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:56.364281071Z 37 PC: 13661 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:56.365511841Z 37 PC: 13661 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:56.36704505Z 37 PC: 13661 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:56.367870771Z 37 PC: 13661 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:56.368615576Z 76 PC: 136a0 | Terminate with return code (Return code = '0')