Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Hitman.7488

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:57.238288758Z 53 PC: 1395a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:57.240096016Z 53 PC: 1395a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:57.241847801Z 53 PC: 1395a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:57.244222617Z 53 PC: 1395a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:57.249321705Z 53 PC: 1395a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:57.251971398Z 53 PC: 1395a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.254538286Z 53 PC: 1395a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:57.257271225Z 53 PC: 1395a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:57.258679683Z 53 PC: 1395a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:57.260050541Z 53 PC: 1395a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:57.262232514Z 53 PC: 1395a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:57.264693753Z 53 PC: 1395a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:57.266291357Z 53 PC: 1395a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:57.272314604Z 53 PC: 1395a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:57.273605081Z 53 PC: 1395a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:57.274702775Z 53 PC: 1395a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:57.27686429Z 53 PC: 1395a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:57.278196075Z 53 PC: 1395a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:57.280030584Z 53 PC: 1395a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:57.282006159Z 37 PC: 1396f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:57.288772975Z 37 PC: 13977 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:57.290417056Z 37 PC: 1397f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.29240764Z 37 PC: 13987 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:57.294328582Z 68 PC: 14448 | I/O control for devices (Set for = '')
2018-12-17T22:55:57.40276027Z 37 PC: 131a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:57.405574131Z 48 PC: 1416e | Get DOS version
2018-12-17T22:55:57.411526474Z 26 PC: 137cd | Set disk transfer address
2018-12-17T22:55:57.413106025Z 78 PC: 137d9 | Find first file
2018-12-17T22:55:57.420425459Z 67 PC: 13756 | Get or set file attributes
2018-12-17T22:55:57.440910522Z 61 PC: 14020 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:55:57.448546592Z 66 PC: 14152 | Move file pointer
2018-12-17T22:55:57.45075229Z 63 PC: 140f3 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:55:57.46011147Z 62 PC: 14070 | Close file
2018-12-17T22:55:57.462532693Z 67 PC: 13756 | Get or set file attributes
2018-12-17T22:55:57.47421943Z 87 PC: 1379d | Get or set file date and time
2018-12-17T22:55:57.477102411Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T22:55:57.479145323Z 79 PC: 137f6 | Find next file
2018-12-17T22:55:57.482332707Z 26 PC: 137cd | Set disk transfer address
2018-12-17T22:55:57.484634145Z 78 PC: 137d9 | Find first file
2018-12-17T22:55:57.49193797Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T22:55:57.493557255Z 79 PC: 137f6 | Find next file
2018-12-17T22:55:57.496619013Z 48 PC: 1416e | Get DOS version
2018-12-17T22:55:57.499329791Z 26 PC: 137cd | Set disk transfer address
2018-12-17T22:55:57.500625737Z 78 PC: 137d9 | Find first file
2018-12-17T22:55:57.511616185Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:57.513701887Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:57.5150325Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:57.516272872Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:57.518294584Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:57.520028655Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.521859759Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:57.524327319Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:57.525917088Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:57.527584263Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:57.529251589Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:57.531848803Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:57.533494578Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:57.535349276Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:57.53793059Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:57.539516312Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:57.541234863Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:57.543666947Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:57.545636842Z 37 PC: 13ab1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:57.54725234Z 76 PC: 13af0 | Terminate with return code (Return code = '0')