Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Test.5760

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:24.47401695Z 53 PC: 1316a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:24.4763675Z 53 PC: 1316a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:24.477969863Z 53 PC: 1316a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:24.479310734Z 53 PC: 1316a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:24.483044845Z 53 PC: 1316a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:24.484546308Z 53 PC: 1316a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:24.485810215Z 53 PC: 1316a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:24.487247758Z 53 PC: 1316a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:24.495078983Z 53 PC: 1316a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:24.496458898Z 53 PC: 1316a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:24.497671628Z 53 PC: 1316a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:24.501097299Z 53 PC: 1316a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:24.50232647Z 53 PC: 1316a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:24.503674616Z 53 PC: 1316a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:24.506632227Z 53 PC: 1316a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:24.507979871Z 53 PC: 1316a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:24.509182432Z 53 PC: 1316a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:24.511409991Z 53 PC: 1316a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:24.512697482Z 53 PC: 1316a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:24.514192994Z 37 PC: 1317f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:24.516657558Z 37 PC: 13187 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:24.518138101Z 37 PC: 1318f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:24.519322929Z 37 PC: 13197 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:24.521671746Z 68 PC: 13d7c | I/O control for devices (Set for = '')
2018-12-17T22:56:24.523215028Z 48 PC: 1397e | Get DOS version
2018-12-17T22:56:24.52463628Z 67 PC: 12ecf | Get or set file attributes
2018-12-17T22:56:24.529965852Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T22:56:24.547741715Z 61 PC: 13830 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:56:24.559155617Z 63 PC: 13903 | Read file or device (Read 5760 bytes on handle 5)
2018-12-17T22:56:24.572684857Z 87 PC: 12f3d | Get or set file date and time
2018-12-17T22:56:24.576273324Z 62 PC: 13880 | Close file
2018-12-17T22:56:24.589987671Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T22:56:24.601039532Z 26 PC: 12f6d | Set disk transfer address
2018-12-17T22:56:24.603647977Z 78 PC: 12f79 | Find first file
2018-12-17T22:56:24.611021662Z 26 PC: 12f91 | Set disk transfer address
2018-12-17T22:56:24.612728972Z 79 PC: 12f96 | Find next file
2018-12-17T22:56:24.616633113Z 48 PC: 1397e | Get DOS version
2018-12-17T22:56:24.618680723Z 48 PC: 1397e | Get DOS version
2018-12-17T22:56:24.620532405Z 67 PC: 12ecf | Get or set file attributes
2018-12-17T22:56:24.627841378Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T22:56:24.641843306Z 61 PC: 13830 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:56:24.649359048Z 66 PC: 13e7b | Move file pointer
2018-12-17T22:56:24.65251397Z 66 PC: 13e89 | Move file pointer
2018-12-17T22:56:24.654482381Z 66 PC: 13e97 | Move file pointer
2018-12-17T22:56:24.656464418Z 66 PC: 13962 | Move file pointer
2018-12-17T22:56:24.658662641Z 63 PC: 13903 | Read file or device (Read 5760 bytes on handle 5)
2018-12-17T22:56:24.667817355Z 66 PC: 13962 | Move file pointer
2018-12-17T22:56:24.6697874Z 64 PC: 13903 | Write file or device (Write 5760 bytes on handle 5)
2018-12-17T22:56:24.679281582Z 87 PC: 12f3d | Get or set file date and time
2018-12-17T22:56:24.682310938Z 62 PC: 13880 | Close file
2018-12-17T22:56:24.691088903Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T22:56:24.70185131Z 53 PC: 130dc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:24.704114646Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:24.705758046Z 53 PC: 130dc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:24.708159711Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:24.710467761Z 53 PC: 130dc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:24.712360721Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:24.713864829Z 53 PC: 130dc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:24.716173019Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:24.718024941Z 53 PC: 130dc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:24.719539078Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:24.72194922Z 53 PC: 130dc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:24.724173763Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:24.726773642Z 53 PC: 130dc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:24.728365094Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:24.730852662Z 53 PC: 130dc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:24.732665941Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:24.734601651Z 53 PC: 130dc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:24.737257164Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:24.739023305Z 53 PC: 130dc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:24.740941141Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:24.743922177Z 53 PC: 130dc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:24.746387562Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:24.748740617Z 53 PC: 130dc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:24.751732682Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:24.753325788Z 53 PC: 130dc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:24.754884839Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:24.758140922Z 53 PC: 130dc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:24.759822283Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:24.761881485Z 53 PC: 130dc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:24.7641709Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:24.770183496Z 53 PC: 130dc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:24.772262946Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:24.776280219Z 53 PC: 130dc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:24.779184801Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:24.780903934Z 53 PC: 130dc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:24.782650778Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:24.785304688Z 53 PC: 130dc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:24.787009274Z 37 PC: 130e5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:24.789105736Z 41 PC: 13093 | Parse filename
2018-12-17T22:56:24.793433914Z 41 PC: 130a1 | Parse filename
2018-12-17T22:56:24.795354305Z 75 PC: 130ac | Execute program
2018-12-17T22:56:24.835226738Z 80 PC: 1e909 | Set current PSP
2018-12-17T22:56:24.836631369Z 48 PC: 1e90e | Get DOS version
2018-12-17T22:56:24.838896107Z 99 PC: 250f0 | Get DBCS lead byte table pointer
2018-12-17T22:56:24.842016124Z 101 PC: 1e994 | Get extended country info
2018-12-17T22:56:24.843685974Z 99 PC: 1e99a | Get DBCS lead byte table pointer
2018-12-17T22:56:24.8456733Z 74 PC: 1e9fc | Reallocate memory
2018-12-17T22:56:24.8472846Z 25 PC: 1ea33 | Get default drive
2018-12-17T22:56:24.848727814Z 37 PC: 1e4f3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:56:24.850766187Z 37 PC: 1e4fa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:24.852280093Z 37 PC: 1e501 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:24.85716073Z 74 PC: 1d69c | Reallocate memory
2018-12-17T22:56:24.85983601Z 72 PC: 1d6dd | Allocate memory
2018-12-17T22:56:24.861844647Z 72 PC: 1d715 | Allocate memory
2018-12-17T22:56:24.863929828Z 72 PC: 1d71d | Allocate memory