Sample viewer

vx.netlux.org/Virus.DOS.HLLP.7529

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:18.666644544Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:18.668969364Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:18.670824972Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:18.672473041Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:18.674086474Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:18.676592054Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:18.678095751Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:18.679829871Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:18.682678717Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:18.684654912Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:18.686476928Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:18.695197332Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:18.697826184Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:18.700199085Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:18.703505651Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:18.705976195Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:18.707684206Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:18.709323408Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:18.712389452Z 53 PC: 13df2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:18.714187983Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:18.715728509Z 37 PC: 13e0f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:18.718406093Z 37 PC: 13e17 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:18.72093093Z 37 PC: 13e1f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:18.725405021Z 68 PC: 1418f | I/O control for devices (Set for = '')
2018-12-17T22:57:18.757800093Z 37 PC: 13445 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:18.760145542Z 48 PC: 139d4 | Get DOS version
2018-12-17T22:57:18.762209342Z 48 PC: 139d4 | Get DOS version
2018-12-17T22:57:18.770584888Z 48 PC: 14e22 | Get DOS version
2018-12-17T22:57:18.772802356Z 54 PC: 13a51 | Get free disk space
2018-12-17T22:57:18.783350827Z 60 PC: 14bab | Create or truncate file
2018-12-17T22:57:18.802776106Z 62 PC: 14bfb | Close file
2018-12-17T22:57:18.805523341Z 65 PC: 14d80 | Delete file (Filename = 'A:\$$$ %')
2018-12-17T22:57:18.818814377Z 48 PC: 14e22 | Get DOS version
2018-12-17T22:57:18.821307224Z 67 PC: 13a8a | Get or set file attributes
2018-12-17T22:57:18.828699752Z 67 PC: 13ab1 | Get or set file attributes
2018-12-17T22:57:18.840344664Z 61 PC: 14bab | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:57:18.848746238Z 63 PC: 14c7e | Read file or device (Read 7529 bytes on handle 5)
2018-12-17T22:57:18.857998011Z 66 PC: 14d47 | Move file pointer
2018-12-17T22:57:18.859820247Z 66 PC: 14d55 | Move file pointer
2018-12-17T22:57:18.861679382Z 66 PC: 14d63 | Move file pointer
2018-12-17T22:57:18.864186055Z 62 PC: 14bfb | Close file
2018-12-17T22:57:18.866152922Z 67 PC: 13ab1 | Get or set file attributes
2018-12-17T22:57:18.88368413Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:18.885904855Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:18.887830966Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:18.889468946Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:18.891948106Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:18.893736969Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:18.895346936Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:18.897894305Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:18.903369999Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:18.905362816Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:18.907125189Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:18.910743681Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:18.912218103Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:18.913692665Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:18.915379517Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:18.916729835Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:18.918033947Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:18.920277163Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:18.921707442Z 37 PC: 13f06 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:18.923060215Z 76 PC: 13f45 | Terminate with return code (Return code = '3')