Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DeepThough.13120

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:07.634610024Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:57:07.637255184Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:07.638837481Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:57:07.640662877Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:57:07.642844888Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:57:07.645397111Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:07.648101211Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:57:07.651843482Z 68 PC: 1440d | I/O control for devices (Set for = '��')
2018-12-17T22:57:07.655974502Z 68 PC: 1440d | I/O control for devices (Set for = '��')
2018-12-17T22:57:07.65999978Z 42 PC: 135ee | Get date 0x135ee: mov word ptr [si], cx
0x135f0: mov word ptr [si + 2], dx
0x135f3: pop si
0x135f4: pop bp
0x135f5: ret
0x135f6: push bp
0x135f7: mov bp, sp
0x135f9: push si
0x135fa: mov si, word ptr [bp + 4]
0x135fd: mov ah, 0x2c
0x135ff: int 0x21
0x13601: mov word ptr [si], cx
0x13603: mov word ptr [si + 2], dx
0x13606: pop si
0x13607: pop bp
0x13608: ret
0x13609: mov ax, 0x3700
0x1360c: int 0x21
0x1360e: mov al, dl
0x13610: mov ah, 0
2018-12-17T22:57:07.663547185Z 44 PC: 13601 | Get time 0x13601: mov word ptr [si], cx
0x13603: mov word ptr [si + 2], dx
0x13606: pop si
0x13607: pop bp
0x13608: ret
0x13609: mov ax, 0x3700
0x1360c: int 0x21
0x1360e: mov al, dl
0x13610: mov ah, 0
0x13612: ret
0x13613: push bp
0x13614: mov bp, sp
0x13616: mov ax, 0x3701
0x13619: mov dl, byte ptr [bp + 4]
0x1361c: int 0x21
0x1361e: pop bp
0x1361f: ret
0x13620: push bp
0x13621: mov bp, sp
0x13623: mov ax, 0xd27
2018-12-17T22:57:07.667916581Z 47 PC: 141ac | Get disk transfer address
2018-12-17T22:57:07.669195929Z 26 PC: 141b5 | Set disk transfer address
2018-12-17T22:57:07.670665591Z 78 PC: 141bf | Find first file
2018-12-17T22:57:07.679238177Z 26 PC: 141c7 | Set disk transfer address
2018-12-17T22:57:07.682165896Z 47 PC: 141ac | Get disk transfer address
2018-12-17T22:57:07.683920801Z 26 PC: 141b5 | Set disk transfer address
2018-12-17T22:57:07.68678891Z 78 PC: 141bf | Find first file
2018-12-17T22:57:07.693883556Z 26 PC: 141c7 | Set disk transfer address
2018-12-17T22:57:07.695874854Z 47 PC: 141de | Get disk transfer address
2018-12-17T22:57:07.698937771Z 26 PC: 141e7 | Set disk transfer address
2018-12-17T22:57:07.700960735Z 79 PC: 141eb | Find next file
2018-12-17T22:57:07.704052428Z 26 PC: 141f3 | Set disk transfer address
2018-12-17T22:57:07.706365658Z 86 PC: 14805 | Rename file
2018-12-17T22:57:07.742642075Z 61 PC: 14700 | Open file (Filename = 'temp.exe')
2018-12-17T22:57:07.750651826Z 68 PC: 143b1 | I/O control for devices (Set for = 'pyright 1990 Borland Intl.')
2018-12-17T22:57:07.753464337Z 68 PC: 1440d | I/O control for devices (Set for = 'z{|}~')
2018-12-17T22:57:07.756497937Z 67 PC: 14113 | Get or set file attributes
2018-12-17T22:57:07.763837944Z 60 PC: 1458d | Create or truncate file
2018-12-17T22:57:07.776666704Z 68 PC: 1440d | I/O control for devices (Set for = '')
2018-12-17T22:57:07.779612402Z 66 PC: 14431 | Move file pointer
2018-12-17T22:57:07.781905786Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.791102407Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.80045285Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.811580005Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.820697358Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.833307949Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.841745814Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.853241977Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.862666113Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.874041041Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.8829282Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.894689411Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.903235643Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.912329813Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.917066205Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.92369753Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.928529356Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.93582248Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.945792245Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.957374913Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.965393017Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.977156376Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:07.985238791Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:07.995895881Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.004712786Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.016542951Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.024810458Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.036284077Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.051931941Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.062747593Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.06821007Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.079794456Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.088913212Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.101850437Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.112291714Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.119204395Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.124203681Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.132324101Z 63 PC: 147e9 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:57:08.138030835Z 64 PC: 150bf | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:57:08.14439402Z 64 PC: 150bf | Write file or device (Write 357 bytes on handle 6)
2018-12-17T22:57:08.149335698Z 62 PC: 14128 | Close file
2018-12-17T22:57:08.155091896Z 62 PC: 14128 | Close file
2018-12-17T22:57:08.157035897Z 55 PC: 1360e | Get or set switch character
2018-12-17T22:57:08.159227188Z 41 PC: 155bd | Parse filename
2018-12-17T22:57:08.161090582Z 41 PC: 155cb | Parse filename
2018-12-17T22:57:08.162436954Z 75 PC: 1560b | Execute program
2018-12-17T22:57:08.184759453Z 80 PC: 26d49 | Set current PSP
2018-12-17T22:57:08.185656668Z 48 PC: 26d4e | Get DOS version
2018-12-17T22:57:08.187308457Z 99 PC: 2d530 | Get DBCS lead byte table pointer
2018-12-17T22:57:08.190501996Z 101 PC: 26dd4 | Get extended country info
2018-12-17T22:57:08.191806692Z 99 PC: 26dda | Get DBCS lead byte table pointer
2018-12-17T22:57:08.193284957Z 74 PC: 26e3c | Reallocate memory
2018-12-17T22:57:08.195169053Z 25 PC: 26e73 | Get default drive
2018-12-17T22:57:08.196447502Z 37 PC: 26933 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:57:08.197723903Z 37 PC: 2693a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:08.199588988Z 37 PC: 26941 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:08.205561412Z 74 PC: 25adc | Reallocate memory
2018-12-17T22:57:08.207455593Z 72 PC: 25b1d | Allocate memory
2018-12-17T22:57:08.209634217Z 72 PC: 25b55 | Allocate memory
2018-12-17T22:57:08.212741062Z 72 PC: 25b5d | Allocate memory