Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Kobr.8636

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:52.542537193Z 53 PC: 1389a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:52.548794321Z 53 PC: 1389a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:52.550134584Z 53 PC: 1389a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:52.551423555Z 53 PC: 1389a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:52.553508718Z 53 PC: 1389a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:52.55554679Z 53 PC: 1389a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:52.557308326Z 53 PC: 1389a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:52.559990399Z 53 PC: 1389a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:52.562291042Z 53 PC: 1389a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:52.563897409Z 53 PC: 1389a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:52.565771227Z 53 PC: 1389a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:52.567891381Z 53 PC: 1389a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:52.56909101Z 53 PC: 1389a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:52.582728118Z 53 PC: 1389a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:52.584256061Z 53 PC: 1389a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:52.585385697Z 53 PC: 1389a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:52.586987276Z 53 PC: 1389a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:52.589011169Z 53 PC: 1389a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:52.59109221Z 53 PC: 1389a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:52.593471852Z 37 PC: 138af | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:52.595753008Z 37 PC: 138b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:52.597841004Z 37 PC: 138bf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:52.617491842Z 37 PC: 138c7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:52.619817269Z 68 PC: 14745 | I/O control for devices (Set for = '���')
2018-12-17T22:54:52.621625286Z 26 PC: 13635 | Set disk transfer address
2018-12-17T22:54:52.623379871Z 78 PC: 13641 | Find first file
2018-12-17T22:54:52.629822055Z 60 PC: 14729 | Create or truncate file
2018-12-17T22:54:52.646691376Z 68 PC: 14745 | I/O control for devices (Set for = '���')
2018-12-17T22:54:52.648986808Z 64 PC: 13ef6 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:54:52.653250769Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.664517009Z 61 PC: 14729 | Open file (Filename = '!6')
2018-12-17T22:54:52.67449234Z 63 PC: 13ec4 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:54:52.678509811Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.680299563Z 65 PC: 14356 | Delete file (Filename = '!6')
2018-12-17T22:54:52.694094193Z 26 PC: 13659 | Set disk transfer address
2018-12-17T22:54:52.705202445Z 79 PC: 1365e | Find next file
2018-12-17T22:54:52.713989037Z 60 PC: 14729 | Create or truncate file
2018-12-17T22:54:52.725856171Z 68 PC: 14745 | I/O control for devices (Set for = '���')
2018-12-17T22:54:52.727597943Z 26 PC: 13635 | Set disk transfer address
2018-12-17T22:54:52.72871549Z 78 PC: 13641 | Find first file
2018-12-17T22:54:52.735685204Z 64 PC: 13ef6 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:54:52.738054785Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.745283427Z 61 PC: 14729 | Open file (Filename = '!7')
2018-12-17T22:54:52.751715954Z 68 PC: 14745 | I/O control for devices (Set for = '���')
2018-12-17T22:54:52.753827756Z 66 PC: 14794 | Move file pointer
2018-12-17T22:54:52.755187218Z 66 PC: 147ab | Move file pointer
2018-12-17T22:54:52.756591065Z 63 PC: 147b8 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:54:52.759020135Z 26 PC: 13659 | Set disk transfer address
2018-12-17T22:54:52.760265007Z 79 PC: 1365e | Find next file
2018-12-17T22:54:52.763096242Z 64 PC: 13ef6 | Write file or device (Write 10 bytes on handle 5)
2018-12-17T22:54:52.767317488Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.775283854Z 61 PC: 14729 | Open file (Filename = '!7')
2018-12-17T22:54:52.781843984Z 63 PC: 13ec4 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:54:52.785356238Z 61 PC: 1420d | Open file (Filename = 'TEST.EXE')
2018-12-17T22:54:52.791782146Z 66 PC: 14844 | Move file pointer
2018-12-17T22:54:52.793100848Z 66 PC: 14852 | Move file pointer
2018-12-17T22:54:52.795320243Z 66 PC: 14860 | Move file pointer
2018-12-17T22:54:52.796663172Z 60 PC: 1420d | Create or truncate file
2018-12-17T22:54:52.810778017Z 62 PC: 1425d | Close file
2018-12-17T22:54:52.813780054Z 61 PC: 1420d | Open file (Filename = '!8')
2018-12-17T22:54:52.820297152Z 66 PC: 1433f | Move file pointer
2018-12-17T22:54:52.821852156Z 66 PC: 1433f | Move file pointer
2018-12-17T22:54:52.825062655Z 63 PC: 142e0 | Read file or device (Read 100 bytes on handle 6)
2018-12-17T22:54:52.831712068Z 64 PC: 142e0 | Write file or device (Write 100 bytes on handle 7)
2018-12-17T22:54:52.836174865Z 62 PC: 1425d | Close file
2018-12-17T22:54:52.839055262Z 62 PC: 1425d | Close file
2018-12-17T22:54:52.847205162Z 61 PC: 14729 | Open file (Filename = '!8')
2018-12-17T22:54:52.853677839Z 63 PC: 13ec4 | Read file or device (Read 128 bytes on handle 6)
2018-12-17T22:54:52.857301146Z 63 PC: 13ec4 | Read file or device (Read 128 bytes on handle 6)
2018-12-17T22:54:52.859253002Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.860782298Z 65 PC: 14356 | Delete file (Filename = '!8')
2018-12-17T22:54:52.872291071Z 25 PC: 136e6 | Get default drive
2018-12-17T22:54:52.873141399Z 71 PC: 13705 | Get current directory
2018-12-17T22:54:52.876045931Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.878112408Z 61 PC: 14729 | Open file (Filename = '!7')
2018-12-17T22:54:52.888481455Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.890487549Z 61 PC: 14729 | Open file (Filename = '!7')
2018-12-17T22:54:52.898038311Z 63 PC: 13ec4 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:54:52.905368763Z 63 PC: 13ec4 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:54:52.908296564Z 62 PC: 13f35 | Close file
2018-12-17T22:54:52.911330666Z 65 PC: 14356 | Delete file (Filename = '!7')
2018-12-17T22:54:52.922410048Z 53 PC: 13696 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:54:52.923735673Z 37 PC: 136b2 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:54:52.926242094Z 41 PC: 137fb | Parse filename
2018-12-17T22:54:52.927753817Z 41 PC: 13809 | Parse filename
2018-12-17T22:54:52.929463922Z 75 PC: 13814 | Execute program
2018-12-17T22:54:52.933767822Z 49 PC: 13796 | Terminate and stay resident (Return code = '0' | Memory size = '4855')