Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3678

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:06.298691002Z 53 PC: 13202 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:06.300598259Z 53 PC: 13202 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:06.30195837Z 53 PC: 13202 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:06.303090539Z 53 PC: 13202 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:06.305002569Z 53 PC: 13202 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:06.322292626Z 53 PC: 13202 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:06.323407133Z 53 PC: 13202 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:06.325221626Z 53 PC: 13202 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:06.326494021Z 53 PC: 13202 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:06.32770649Z 53 PC: 13202 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:06.329527647Z 53 PC: 13202 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:06.330658262Z 53 PC: 13202 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:06.331789121Z 53 PC: 13202 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:06.333227598Z 53 PC: 13202 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:06.334746845Z 53 PC: 13202 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:06.335924222Z 53 PC: 13202 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:06.338086018Z 53 PC: 13202 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:06.350203608Z 53 PC: 13202 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:06.35169262Z 53 PC: 13202 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:06.354199968Z 37 PC: 13217 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:06.355600907Z 37 PC: 1321f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:06.357252149Z 37 PC: 13227 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:06.363199222Z 37 PC: 1322f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:06.365151108Z 68 PC: 1354c | I/O control for devices (Set for = '')
2018-12-17T22:54:06.366766582Z 48 PC: 13b7b | Get DOS version
2018-12-17T22:54:06.368530517Z 61 PC: 139a1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:54:06.376466055Z 87 PC: 12f3e | Get or set file date and time
2018-12-17T22:54:06.378729885Z 26 PC: 12f9b | Set disk transfer address
2018-12-17T22:54:06.380044205Z 78 PC: 12fa7 | Find first file
2018-12-17T22:54:06.386546993Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.390701873Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.393577462Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.395406367Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.398339827Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.399297612Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.402455118Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.403405751Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.406210977Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.407470082Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.410183288Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.411077243Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.414650039Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.416105019Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.419177215Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.420788511Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.423645012Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.42460005Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.428779094Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.42983315Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.432591066Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.434259542Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.437181791Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.438140803Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.442202109Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.443405413Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.446304149Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.448216422Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.451736556Z 61 PC: 139a1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:54:06.45816747Z 63 PC: 13a74 | Read file or device (Read 3678 bytes on handle 6)
2018-12-17T22:54:06.466358425Z 66 PC: 13b3d | Move file pointer
2018-12-17T22:54:06.467764135Z 66 PC: 13b4b | Move file pointer
2018-12-17T22:54:06.469428762Z 66 PC: 13b59 | Move file pointer
2018-12-17T22:54:06.472505158Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.474183287Z 64 PC: 13a74 | Write file or device (Write 3678 bytes on handle 6)
2018-12-17T22:54:06.491640932Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.494636585Z 63 PC: 13a74 | Read file or device (Read 3678 bytes on handle 5)
2018-12-17T22:54:06.503980854Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.505594648Z 64 PC: 13a74 | Write file or device (Write 3678 bytes on handle 6)
2018-12-17T22:54:06.514012939Z 87 PC: 12f6b | Get or set file date and time
2018-12-17T22:54:06.515573841Z 62 PC: 139f1 | Close file
2018-12-17T22:54:06.523611586Z 26 PC: 12fbf | Set disk transfer address
2018-12-17T22:54:06.525221567Z 79 PC: 12fc4 | Find next file
2018-12-17T22:54:06.527652108Z 66 PC: 13b3d | Move file pointer
2018-12-17T22:54:06.529095624Z 66 PC: 13b4b | Move file pointer
2018-12-17T22:54:06.531060821Z 66 PC: 13b59 | Move file pointer
2018-12-17T22:54:06.532405575Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.533768978Z 63 PC: 13a74 | Read file or device (Read 3678 bytes on handle 5)
2018-12-17T22:54:06.541256628Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.542496557Z 63 PC: 13a74 | Read file or device (Read 3678 bytes on handle 5)
2018-12-17T22:54:06.549872272Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.551779746Z 64 PC: 13a74 | Write file or device (Write 3678 bytes on handle 5)
2018-12-17T22:54:06.559436488Z 66 PC: 13ad3 | Move file pointer
2018-12-17T22:54:06.560733386Z 64 PC: 13a74 | Write file or device (Write 3678 bytes on handle 5)
2018-12-17T22:54:06.569166495Z 87 PC: 12f6b | Get or set file date and time
2018-12-17T22:54:06.570542012Z 62 PC: 139f1 | Close file
2018-12-17T22:54:06.577909336Z 53 PC: 1307e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:06.579268947Z 37 PC: 13087 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:06.580223401Z 53 PC: 1307e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:06.581205457Z 37 PC: 13087 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:06.583263283Z 53 PC: 1307e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:06.584269136Z 37 PC: 13087 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:06.585230834Z 53 PC: 1307e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:06.586593748Z 37 PC: 13087 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:06.587506958Z 53 PC: 1307e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:06.588401124Z 37 PC: 13087 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:06.589644701Z 53 PC: 1307e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:06.590633461Z 37 PC: 13087 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:06.59147824Z 53 PC: 1307e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:06.592810732Z 37 PC: 13087 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:06.593756663Z 53 PC: 1307e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:06.594742216Z 37 PC: 13087 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:06.596072614Z 53 PC: 1307e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:06.597195728Z 37 PC: 13087 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:06.598377871Z 53 PC: 1307e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:06.599613646Z 37 PC: 13087 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:06.600626829Z 53 PC: 1307e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:06.601588235Z 37 PC: 13087 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:06.602746378Z 53 PC: 1307e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:06.603588542Z 37 PC: 13087 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:06.604416608Z 53 PC: 1307e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:06.605822743Z 37 PC: 13087 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:06.606737257Z 53 PC: 1307e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:06.607576554Z 37 PC: 13087 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:06.608871082Z 53 PC: 1307e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:06.609838684Z 37 PC: 13087 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:06.61080796Z 53 PC: 1307e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:06.612049693Z 37 PC: 13087 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:06.612967213Z 53 PC: 1307e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:06.613817998Z 37 PC: 13087 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:06.615143191Z 53 PC: 1307e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:06.616092663Z 37 PC: 13087 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:06.616982495Z 53 PC: 1307e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:06.618425612Z 37 PC: 13087 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:06.619536083Z 41 PC: 13107 | Parse filename
2018-12-17T22:54:06.620750868Z 41 PC: 13115 | Parse filename
2018-12-17T22:54:06.622975103Z 75 PC: 13120 | Execute program