Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5952

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:41.531648781Z 53 PC: 1320a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:41.533936193Z 53 PC: 1320a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:41.535956903Z 53 PC: 1320a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:41.537479265Z 53 PC: 1320a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:41.538998883Z 53 PC: 1320a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:41.541507441Z 53 PC: 1320a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:41.542991542Z 53 PC: 1320a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:41.544486674Z 53 PC: 1320a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:41.547078098Z 53 PC: 1320a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:41.548902178Z 53 PC: 1320a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:41.550734234Z 53 PC: 1320a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:41.553424694Z 53 PC: 1320a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:41.55504989Z 53 PC: 1320a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:41.557210233Z 53 PC: 1320a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:41.559216887Z 53 PC: 1320a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:41.560573709Z 53 PC: 1320a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:41.561926813Z 53 PC: 1320a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:41.563858767Z 53 PC: 1320a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:41.565587348Z 53 PC: 1320a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:41.567241218Z 37 PC: 1321f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:41.56900244Z 37 PC: 13227 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:41.570891362Z 37 PC: 1322f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:41.572155259Z 37 PC: 13237 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:41.574352671Z 68 PC: 13ead | I/O control for devices (Set for = '��&�<t<�t���������Lr���')
2018-12-17T22:55:41.57656909Z 48 PC: 13af2 | Get DOS version
2018-12-17T22:55:41.578661295Z 61 PC: 13930 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:55:41.586474318Z 60 PC: 13930 | Create or truncate file
2018-12-17T22:55:41.605821865Z 66 PC: 13a62 | Move file pointer
2018-12-17T22:55:41.607816075Z 63 PC: 13a03 | Read file or device (Read 2048 bytes on handle 5)
2018-12-17T22:55:41.610377271Z 62 PC: 13980 | Close file
2018-12-17T22:55:41.613449188Z 62 PC: 13980 | Close file
2018-12-17T22:55:41.616094323Z 53 PC: 13179 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:41.617716544Z 37 PC: 13182 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:41.620416852Z 53 PC: 13179 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:41.622409259Z 37 PC: 13182 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:41.623734161Z 53 PC: 13179 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:41.626148852Z 37 PC: 13182 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:41.627643964Z 53 PC: 13179 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:41.629079083Z 37 PC: 13182 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:41.630634278Z 53 PC: 13179 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:41.632589555Z 37 PC: 13182 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:41.634268673Z 53 PC: 13179 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:41.635930078Z 37 PC: 13182 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:41.63803703Z 53 PC: 13179 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:41.639675221Z 37 PC: 13182 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:41.641327278Z 53 PC: 13179 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:41.643548705Z 37 PC: 13182 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:41.644821088Z 53 PC: 13179 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:41.646115352Z 37 PC: 13182 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:41.648718077Z 53 PC: 13179 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:41.650242143Z 37 PC: 13182 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:41.65242582Z 53 PC: 13179 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:41.654540136Z 37 PC: 13182 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:41.655912307Z 53 PC: 13179 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:41.65725403Z 37 PC: 13182 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:41.659666988Z 53 PC: 13179 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:41.661284971Z 37 PC: 13182 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:41.662871465Z 53 PC: 13179 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:41.664726794Z 37 PC: 13182 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:41.667049853Z 53 PC: 13179 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:41.668688034Z 37 PC: 13182 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:41.670235755Z 53 PC: 13179 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:41.672517055Z 37 PC: 13182 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:41.67385433Z 53 PC: 13179 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:41.675177308Z 37 PC: 13182 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:41.677129389Z 53 PC: 13179 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:41.678722865Z 37 PC: 13182 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:41.680292197Z 53 PC: 13179 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:41.682594727Z 37 PC: 13182 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:41.684718491Z 41 PC: 13130 | Parse filename
2018-12-17T22:55:41.686583789Z 41 PC: 1313e | Parse filename
2018-12-17T22:55:41.689123115Z 75 PC: 13149 | Execute program
2018-12-17T22:55:41.713092934Z 80 PC: 1d879 | Set current PSP
2018-12-17T22:55:41.714334358Z 48 PC: 1d87e | Get DOS version
2018-12-17T22:55:41.716954516Z 99 PC: 24060 | Get DBCS lead byte table pointer
2018-12-17T22:55:41.720163962Z 101 PC: 1d904 | Get extended country info
2018-12-17T22:55:41.721593651Z 99 PC: 1d90a | Get DBCS lead byte table pointer
2018-12-17T22:55:41.723931417Z 74 PC: 1d96c | Reallocate memory
2018-12-17T22:55:41.725946026Z 25 PC: 1d9a3 | Get default drive
2018-12-17T22:55:41.727180728Z 37 PC: 1d463 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:55:41.728416282Z 37 PC: 1d46a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:41.730134984Z 37 PC: 1d471 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:41.734758179Z 74 PC: 1c60c | Reallocate memory
2018-12-17T22:55:41.737569827Z 72 PC: 1c64d | Allocate memory
2018-12-17T22:55:41.740758063Z 72 PC: 1c685 | Allocate memory
2018-12-17T22:55:41.742659669Z 72 PC: 1c68d | Allocate memory