Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Niki.7412

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:38.123318634Z 53 PC: 1385a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:38.124990916Z 53 PC: 1385a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:38.129039882Z 53 PC: 1385a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:38.130109014Z 53 PC: 1385a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:38.132197622Z 53 PC: 1385a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:38.133219398Z 53 PC: 1385a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:38.134203361Z 53 PC: 1385a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:38.135873708Z 53 PC: 1385a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:38.136916329Z 53 PC: 1385a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:38.138003412Z 53 PC: 1385a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:38.139917407Z 53 PC: 1385a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:38.141215293Z 53 PC: 1385a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:38.142682047Z 53 PC: 1385a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:38.144442108Z 53 PC: 1385a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:38.146441462Z 53 PC: 1385a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:38.147864886Z 53 PC: 1385a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:38.149272857Z 53 PC: 1385a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:38.151799855Z 53 PC: 1385a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:38.153232626Z 53 PC: 1385a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:38.154667126Z 37 PC: 1386f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:38.157858893Z 37 PC: 13877 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:38.158876513Z 37 PC: 1387f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:38.159908001Z 37 PC: 13887 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:38.162262147Z 68 PC: 143b7 | I/O control for devices (Set for = '')
2018-12-17T22:56:38.164219714Z 60 PC: 13f20 | Create or truncate file
2018-12-17T22:56:38.181843577Z 65 PC: 14069 | Delete file (Filename = '/�')
2018-12-17T22:56:38.189724006Z 48 PC: 140e2 | Get DOS version
2018-12-17T22:56:38.191386158Z 67 PC: 135e8 | Get or set file attributes
2018-12-17T22:56:38.201703685Z 61 PC: 13f20 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:56:38.208948442Z 66 PC: 14052 | Move file pointer
2018-12-17T22:56:38.210531616Z 63 PC: 13ff3 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:56:38.217479129Z 87 PC: 1362f | Get or set file date and time
2018-12-17T22:56:38.220105579Z 67 PC: 135e8 | Get or set file attributes
2018-12-17T22:56:38.230245446Z 62 PC: 13f70 | Close file
2018-12-17T22:56:38.237376795Z 48 PC: 140e2 | Get DOS version
2018-12-17T22:56:38.239479471Z 61 PC: 13f20 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:56:38.246433078Z 63 PC: 13ff3 | Read file or device (Read 7408 bytes on handle 6)
2018-12-17T22:56:38.254251292Z 62 PC: 13f70 | Close file
2018-12-17T22:56:38.257329651Z 26 PC: 1365f | Set disk transfer address
2018-12-17T22:56:38.258679118Z 78 PC: 1366b | Find first file
2018-12-17T22:56:38.270014001Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.271903985Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.275110384Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.2761855Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.279927097Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.280883582Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.283915512Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.285754971Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.288917421Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.289933113Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.294210012Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.295435935Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.298676454Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.300926794Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.30404183Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.305022776Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.308201164Z 48 PC: 140e2 | Get DOS version
2018-12-17T22:56:38.310531957Z 26 PC: 1365f | Set disk transfer address
2018-12-17T22:56:38.311773277Z 78 PC: 1366b | Find first file
2018-12-17T22:56:38.326406506Z 67 PC: 135e8 | Get or set file attributes
2018-12-17T22:56:38.337114192Z 61 PC: 13f20 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:56:38.344438098Z 66 PC: 14052 | Move file pointer
2018-12-17T22:56:38.347411342Z 63 PC: 13ff3 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:56:38.355066561Z 62 PC: 13f70 | Close file
2018-12-17T22:56:38.356899315Z 26 PC: 13683 | Set disk transfer address
2018-12-17T22:56:38.358239474Z 79 PC: 13688 | Find next file
2018-12-17T22:56:38.365055144Z 48 PC: 140e2 | Get DOS version
2018-12-17T22:56:38.366459827Z 26 PC: 1365f | Set disk transfer address
2018-12-17T22:56:38.367797792Z 78 PC: 1366b | Find first file
2018-12-17T22:56:38.375066841Z 61 PC: 13f20 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:56:38.381947106Z 67 PC: 135e8 | Get or set file attributes
2018-12-17T22:56:38.391979169Z 62 PC: 13f70 | Close file
2018-12-17T22:56:38.394640845Z 61 PC: 13f20 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:56:38.401327209Z 66 PC: 14052 | Move file pointer
2018-12-17T22:56:38.402897256Z 63 PC: 13ff3 | Read file or device (Read 7412 bytes on handle 6)
2018-12-17T22:56:38.411332486Z 66 PC: 14052 | Move file pointer
2018-12-17T22:56:38.412708405Z 63 PC: 13ff3 | Read file or device (Read 7412 bytes on handle 6)
2018-12-17T22:56:38.421012991Z 66 PC: 14052 | Move file pointer
2018-12-17T22:56:38.42364879Z 64 PC: 13ff3 | Write file or device (Write 7412 bytes on handle 6)
2018-12-17T22:56:38.431726111Z 66 PC: 14052 | Move file pointer
2018-12-17T22:56:38.433027532Z 64 PC: 13f51 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T22:56:38.441339289Z 87 PC: 1362f | Get or set file date and time
2018-12-17T22:56:38.442850157Z 67 PC: 135e8 | Get or set file attributes
2018-12-17T22:56:38.452369052Z 62 PC: 13f70 | Close file
2018-12-17T22:56:38.459575604Z 48 PC: 140e2 | Get DOS version
2018-12-17T22:56:38.460807509Z 26 PC: 1365f | Set disk transfer address
2018-12-17T22:56:38.46183467Z 78 PC: 1366b | Find first file
2018-12-17T22:56:38.466626243Z 53 PC: 137ce | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:38.46780003Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:38.468997361Z 53 PC: 137ce | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:38.471238241Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:38.472351238Z 53 PC: 137ce | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:38.473566725Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:38.475497122Z 53 PC: 137ce | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:38.476664032Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:38.477761079Z 53 PC: 137ce | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:38.479893729Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:38.481011521Z 53 PC: 137ce | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:38.482153899Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:38.484184252Z 53 PC: 137ce | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:38.485324786Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:38.486395411Z 53 PC: 137ce | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:38.48882436Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:38.489875111Z 53 PC: 137ce | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:38.49094631Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:38.4922274Z 53 PC: 137ce | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:38.49438414Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:38.49611384Z 53 PC: 137ce | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:38.497189575Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:38.499515261Z 53 PC: 137ce | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:38.500819583Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:38.502130372Z 53 PC: 137ce | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:38.504404421Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:38.506279403Z 53 PC: 137ce | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:38.507616733Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:38.510132805Z 53 PC: 137ce | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:38.511227426Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:38.512908215Z 53 PC: 137ce | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:38.515202095Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:38.516605617Z 53 PC: 137ce | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:38.518078948Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:38.520107648Z 53 PC: 137ce | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:38.521646834Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:38.52303936Z 53 PC: 137ce | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:38.524836433Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:38.526475291Z 41 PC: 13785 | Parse filename
2018-12-17T22:56:38.527740952Z 41 PC: 13793 | Parse filename
2018-12-17T22:56:38.529954988Z 75 PC: 1379e | Execute program
2018-12-17T22:56:38.551222844Z 80 PC: 1bea9 | Set current PSP
2018-12-17T22:56:38.552098362Z 48 PC: 1beae | Get DOS version
2018-12-17T22:56:38.554912852Z 99 PC: 22690 | Get DBCS lead byte table pointer
2018-12-17T22:56:38.557521389Z 101 PC: 1bf34 | Get extended country info
2018-12-17T22:56:38.558991127Z 99 PC: 1bf3a | Get DBCS lead byte table pointer
2018-12-17T22:56:38.561081371Z 74 PC: 1bf9c | Reallocate memory
2018-12-17T22:56:38.562756446Z 25 PC: 1bfd3 | Get default drive
2018-12-17T22:56:38.564112105Z 37 PC: 1ba93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:56:38.566496091Z 37 PC: 1ba9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:38.567870673Z 37 PC: 1baa1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:38.572070436Z 74 PC: 1ac3c | Reallocate memory
2018-12-17T22:56:38.574445652Z 72 PC: 1ac7d | Allocate memory
2018-12-17T22:56:38.576045232Z 72 PC: 1acb5 | Allocate memory
2018-12-17T22:56:38.577906981Z 72 PC: 1acbd | Allocate memory