Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DNVG.4997

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:52.279581488Z 53 PC: 132ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:52.281665187Z 53 PC: 132ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:52.282772277Z 53 PC: 132ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:52.283837844Z 53 PC: 132ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:52.285922453Z 53 PC: 132ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:52.287445547Z 53 PC: 132ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:52.288976459Z 53 PC: 132ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:52.290474072Z 53 PC: 132ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:52.292565389Z 53 PC: 132ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:52.29407262Z 53 PC: 132ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:52.295602442Z 53 PC: 132ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:52.298407172Z 53 PC: 132ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:52.29988868Z 53 PC: 132ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:52.301362712Z 53 PC: 132ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:52.305162515Z 53 PC: 132ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:52.30691137Z 53 PC: 132ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:52.308346008Z 53 PC: 132ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:52.310716614Z 53 PC: 132ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:52.312743934Z 53 PC: 132ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:52.314722455Z 37 PC: 132cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:52.318657395Z 37 PC: 132d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:52.319900171Z 37 PC: 132df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:52.321394065Z 37 PC: 132e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:52.32875699Z 68 PC: 13b4a | I/O control for devices (Set for = '')
2018-12-17T22:55:52.33055547Z 48 PC: 13870 | Get DOS version
2018-12-17T22:55:52.333182229Z 48 PC: 13870 | Get DOS version
2018-12-17T22:55:52.336293538Z 61 PC: 13722 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:55:52.343477384Z 63 PC: 137f5 | Read file or device (Read 4992 bytes on handle 5)
2018-12-17T22:55:52.35132337Z 62 PC: 13772 | Close file
2018-12-17T22:55:52.355104887Z 26 PC: 130bd | Set disk transfer address
2018-12-17T22:55:52.356664024Z 78 PC: 130c9 | Find first file
2018-12-17T22:55:52.363883526Z 61 PC: 13722 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:55:52.371731737Z 66 PC: 13854 | Move file pointer
2018-12-17T22:55:52.376470873Z 63 PC: 137f5 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:55:52.383854956Z 26 PC: 130e1 | Set disk transfer address
2018-12-17T22:55:52.386128993Z 79 PC: 130e6 | Find next file
2018-12-17T22:55:52.389680788Z 48 PC: 13870 | Get DOS version
2018-12-17T22:55:52.391176025Z 26 PC: 130bd | Set disk transfer address
2018-12-17T22:55:52.392638131Z 78 PC: 130c9 | Find first file
2018-12-17T22:55:52.399436118Z 48 PC: 13870 | Get DOS version
2018-12-17T22:55:52.405521561Z 67 PC: 13046 | Get or set file attributes
2018-12-17T22:55:52.422154949Z 61 PC: 13722 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:55:52.431575582Z 66 PC: 13854 | Move file pointer
2018-12-17T22:55:52.433404657Z 63 PC: 137f5 | Read file or device (Read 4992 bytes on handle 6)
2018-12-17T22:55:52.441429843Z 66 PC: 13854 | Move file pointer
2018-12-17T22:55:52.44366845Z 64 PC: 13753 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T22:55:52.451960488Z 66 PC: 13854 | Move file pointer
2018-12-17T22:55:52.453656732Z 64 PC: 137f5 | Write file or device (Write 4992 bytes on handle 6)
2018-12-17T22:55:52.461736138Z 87 PC: 1308d | Get or set file date and time
2018-12-17T22:55:52.46350795Z 67 PC: 13046 | Get or set file attributes
2018-12-17T22:55:52.473945316Z 62 PC: 13772 | Close file
2018-12-17T22:55:52.481854324Z 53 PC: 1322c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:52.483064118Z 37 PC: 13235 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:52.484213036Z 53 PC: 1322c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:52.486374603Z 37 PC: 13235 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:52.487592064Z 53 PC: 1322c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:52.488739094Z 37 PC: 13235 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:52.491169Z 53 PC: 1322c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:52.4928427Z 37 PC: 13235 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:52.494528943Z 53 PC: 1322c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:52.497208045Z 37 PC: 13235 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:52.499439444Z 53 PC: 1322c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:52.501074627Z 37 PC: 13235 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:52.503586343Z 53 PC: 1322c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:52.505023082Z 37 PC: 13235 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:52.50691406Z 53 PC: 1322c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:52.508620115Z 37 PC: 13235 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:52.510159052Z 53 PC: 1322c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:52.51193573Z 37 PC: 13235 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:52.513807184Z 53 PC: 1322c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:52.515079817Z 37 PC: 13235 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:52.516186402Z 53 PC: 1322c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:52.518306061Z 37 PC: 13235 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:52.519518567Z 53 PC: 1322c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:52.520632151Z 37 PC: 13235 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:52.522297645Z 53 PC: 1322c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:52.523895407Z 37 PC: 13235 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:52.526071731Z 53 PC: 1322c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:52.53284966Z 37 PC: 13235 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:52.53445382Z 53 PC: 1322c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:52.536202872Z 37 PC: 13235 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:52.538222855Z 53 PC: 1322c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:52.539861739Z 37 PC: 13235 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:52.541348362Z 53 PC: 1322c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:52.543432786Z 37 PC: 13235 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:52.545169463Z 53 PC: 1322c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:52.547636108Z 37 PC: 13235 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:52.549931188Z 53 PC: 1322c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:52.551578184Z 37 PC: 13235 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:52.553924401Z 41 PC: 131e3 | Parse filename
2018-12-17T22:55:52.55696212Z 41 PC: 131f1 | Parse filename
2018-12-17T22:55:52.558907024Z 75 PC: 131fc | Execute program
2018-12-17T22:55:52.586238351Z 80 PC: 187f9 | Set current PSP
2018-12-17T22:55:52.588903756Z 48 PC: 187fe | Get DOS version
2018-12-17T22:55:52.590536717Z 99 PC: 1efe0 | Get DBCS lead byte table pointer
2018-12-17T22:55:52.593151243Z 101 PC: 18884 | Get extended country info
2018-12-17T22:55:52.595657082Z 99 PC: 1888a | Get DBCS lead byte table pointer
2018-12-17T22:55:52.597451144Z 74 PC: 188ec | Reallocate memory
2018-12-17T22:55:52.601001406Z 25 PC: 18923 | Get default drive
2018-12-17T22:55:52.60267765Z 37 PC: 183e3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:55:52.604982442Z 37 PC: 183ea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:52.606447556Z 37 PC: 183f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:52.611876593Z 74 PC: 1758c | Reallocate memory
2018-12-17T22:55:52.61344671Z 72 PC: 175cd | Allocate memory
2018-12-17T22:55:52.61537555Z 72 PC: 17605 | Allocate memory
2018-12-17T22:55:52.617637464Z 72 PC: 1760d | Allocate memory