Sample viewer

vx.netlux.org/Virus.DOS.HLLP.7413

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:59.369455401Z 53 PC: 1378a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:59.373876219Z 53 PC: 1378a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:59.375257306Z 53 PC: 1378a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:59.376590436Z 53 PC: 1378a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:59.38140146Z 53 PC: 1378a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:59.382914302Z 53 PC: 1378a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:59.38432908Z 53 PC: 1378a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:59.386333156Z 53 PC: 1378a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:59.387778441Z 53 PC: 1378a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:59.389282917Z 53 PC: 1378a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:59.391140224Z 53 PC: 1378a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:59.393171638Z 53 PC: 1378a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:59.394759808Z 53 PC: 1378a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:59.396480363Z 53 PC: 1378a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:59.399224462Z 53 PC: 1378a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:59.401734781Z 53 PC: 1378a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:59.404337626Z 53 PC: 1378a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:59.40568864Z 53 PC: 1378a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:59.407660873Z 53 PC: 1378a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:59.408918821Z 37 PC: 1379f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:59.410189884Z 37 PC: 137a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:59.413102774Z 37 PC: 137af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:59.415097645Z 37 PC: 137b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:59.417956211Z 68 PC: 14419 | I/O control for devices (Set for = '')
2018-12-17T22:53:59.531647053Z 37 PC: 12fa1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:59.534223794Z 48 PC: 1402f | Get DOS version
2018-12-17T22:53:59.535997801Z 61 PC: 13ee1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:59.554645187Z 63 PC: 13fb4 | Read file or device (Read 7408 bytes on handle 5)
2018-12-17T22:53:59.564825684Z 62 PC: 13f31 | Close file
2018-12-17T22:53:59.57439964Z 26 PC: 1358b | Set disk transfer address
2018-12-17T22:53:59.575959348Z 78 PC: 13597 | Find first file
2018-12-17T22:53:59.581080584Z 61 PC: 13ee1 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:53:59.585642068Z 66 PC: 14013 | Move file pointer
2018-12-17T22:53:59.587648027Z 63 PC: 13fb4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:53:59.591281715Z 26 PC: 135af | Set disk transfer address
2018-12-17T22:53:59.592474503Z 79 PC: 135b4 | Find next file
2018-12-17T22:53:59.597486336Z 48 PC: 1402f | Get DOS version
2018-12-17T22:53:59.599089986Z 61 PC: 13ee1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:59.603578418Z 66 PC: 14518 | Move file pointer
2018-12-17T22:53:59.604899285Z 66 PC: 14526 | Move file pointer
2018-12-17T22:53:59.607116775Z 66 PC: 14534 | Move file pointer
2018-12-17T22:53:59.608725164Z 66 PC: 14013 | Move file pointer
2018-12-17T22:53:59.610226373Z 63 PC: 13fb4 | Read file or device (Read 7413 bytes on handle 6)
2018-12-17T22:53:59.61652212Z 66 PC: 14013 | Move file pointer
2018-12-17T22:53:59.617842379Z 64 PC: 13fb4 | Write file or device (Write 7413 bytes on handle 6)
2018-12-17T22:53:59.629953411Z 66 PC: 14518 | Move file pointer
2018-12-17T22:53:59.631748033Z 66 PC: 14526 | Move file pointer
2018-12-17T22:53:59.633018556Z 66 PC: 14534 | Move file pointer
2018-12-17T22:53:59.635204514Z 66 PC: 14013 | Move file pointer
2018-12-17T22:53:59.638098381Z 64 PC: 13f12 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T22:53:59.647384619Z 53 PC: 136fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:59.64909804Z 37 PC: 13703 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:59.651529338Z 53 PC: 136fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:59.653308784Z 37 PC: 13703 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:59.654994974Z 53 PC: 136fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:59.657085598Z 37 PC: 13703 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:59.659013573Z 53 PC: 136fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:59.660513889Z 37 PC: 13703 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:59.6619455Z 53 PC: 136fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:59.664126743Z 37 PC: 13703 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:59.665869832Z 53 PC: 136fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:59.667628857Z 37 PC: 13703 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:59.669766145Z 53 PC: 136fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:59.671522264Z 37 PC: 13703 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:59.67322886Z 53 PC: 136fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:59.676628234Z 37 PC: 13703 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:59.678367172Z 53 PC: 136fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:59.680108738Z 37 PC: 13703 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:59.68292116Z 53 PC: 136fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:59.684667482Z 37 PC: 13703 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:59.686381501Z 53 PC: 136fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:59.689011684Z 37 PC: 13703 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:59.690831602Z 53 PC: 136fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:59.692223544Z 37 PC: 13703 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:59.69423621Z 53 PC: 136fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:59.695858222Z 37 PC: 13703 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:59.697476374Z 53 PC: 136fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:59.699833749Z 37 PC: 13703 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:59.701775189Z 53 PC: 136fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:59.70345095Z 37 PC: 13703 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:59.705281487Z 53 PC: 136fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:59.707740141Z 37 PC: 13703 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:59.709357557Z 53 PC: 136fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:59.7118695Z 37 PC: 13703 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:59.714462181Z 53 PC: 136fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:59.716091086Z 37 PC: 13703 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:59.717680834Z 53 PC: 136fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:59.720318288Z 37 PC: 13703 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:59.722388493Z 48 PC: 1402f | Get DOS version
2018-12-17T22:53:59.724572524Z 41 PC: 136b1 | Parse filename
2018-12-17T22:53:59.727097058Z 41 PC: 136bf | Parse filename
2018-12-17T22:53:59.728788816Z 75 PC: 136ca | Execute program
2018-12-17T22:53:59.754422853Z 80 PC: 1a789 | Set current PSP
2018-12-17T22:53:59.756313196Z 48 PC: 1a78e | Get DOS version
2018-12-17T22:53:59.758370142Z 99 PC: 20f70 | Get DBCS lead byte table pointer
2018-12-17T22:53:59.761445812Z 101 PC: 1a814 | Get extended country info
2018-12-17T22:53:59.764446013Z 99 PC: 1a81a | Get DBCS lead byte table pointer
2018-12-17T22:53:59.766086404Z 74 PC: 1a87c | Reallocate memory
2018-12-17T22:53:59.767724074Z 25 PC: 1a8b3 | Get default drive
2018-12-17T22:53:59.769831455Z 37 PC: 1a373 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:53:59.771165566Z 37 PC: 1a37a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:59.772459878Z 37 PC: 1a381 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:59.777712225Z 74 PC: 1951c | Reallocate memory
2018-12-17T22:53:59.779787123Z 72 PC: 1955d | Allocate memory
2018-12-17T22:53:59.782149578Z 72 PC: 19595 | Allocate memory
2018-12-17T22:53:59.784995578Z 72 PC: 1959d | Allocate memory