Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Maxim.5445

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:44.172925885Z 53 PC: 1338a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:44.175518098Z 53 PC: 1338a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:44.177508309Z 53 PC: 1338a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:44.179310677Z 53 PC: 1338a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:44.181373564Z 53 PC: 1338a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:44.188682474Z 53 PC: 1338a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:44.1904144Z 53 PC: 1338a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:44.192462019Z 53 PC: 1338a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:44.196184577Z 53 PC: 1338a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:44.19825576Z 53 PC: 1338a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:44.200864885Z 53 PC: 1338a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:44.204800353Z 53 PC: 1338a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:44.207356488Z 53 PC: 1338a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:44.208918735Z 53 PC: 1338a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:44.214161971Z 53 PC: 1338a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:44.21575224Z 53 PC: 1338a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:44.21732672Z 53 PC: 1338a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:44.219956764Z 53 PC: 1338a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:44.223200011Z 53 PC: 1338a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:44.225361184Z 37 PC: 1339f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:44.227288487Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:44.230144435Z 37 PC: 133af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:44.231949137Z 37 PC: 133b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:44.234218543Z 68 PC: 13c75 | I/O control for devices (Set for = '')
2018-12-17T22:57:44.237326096Z 48 PC: 1399b | Get DOS version
2018-12-17T22:57:44.23946728Z 48 PC: 1399b | Get DOS version
2018-12-17T22:57:44.241514739Z 61 PC: 1384d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:57:44.250320272Z 63 PC: 13920 | Read file or device (Read 5440 bytes on handle 5)
2018-12-17T22:57:44.264566903Z 62 PC: 1389d | Close file
2018-12-17T22:57:44.26795918Z 26 PC: 1318d | Set disk transfer address
2018-12-17T22:57:44.271029371Z 78 PC: 13199 | Find first file
2018-12-17T22:57:44.280025041Z 61 PC: 1384d | Open file (Filename = 'TEST.EXE')
2018-12-17T22:57:44.287683398Z 66 PC: 1397f | Move file pointer
2018-12-17T22:57:44.299643711Z 63 PC: 13920 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:57:44.307148328Z 26 PC: 131b1 | Set disk transfer address
2018-12-17T22:57:44.308717558Z 79 PC: 131b6 | Find next file
2018-12-17T22:57:44.313429576Z 48 PC: 1399b | Get DOS version
2018-12-17T22:57:44.315291185Z 26 PC: 1318d | Set disk transfer address
2018-12-17T22:57:44.316774494Z 78 PC: 13199 | Find first file
2018-12-17T22:57:44.322982093Z 48 PC: 1399b | Get DOS version
2018-12-17T22:57:44.325687569Z 67 PC: 13116 | Get or set file attributes
2018-12-17T22:57:45.023850628Z 61 PC: 1384d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:57:45.030534302Z 66 PC: 1397f | Move file pointer
2018-12-17T22:57:45.033589485Z 63 PC: 13920 | Read file or device (Read 5440 bytes on handle 6)
2018-12-17T22:57:45.043937848Z 66 PC: 1397f | Move file pointer
2018-12-17T22:57:45.045924382Z 64 PC: 1387e | Write file or device (Write 0 bytes on handle 6)
2018-12-17T22:57:45.054607595Z 66 PC: 1397f | Move file pointer
2018-12-17T22:57:45.057309865Z 64 PC: 13920 | Write file or device (Write 5440 bytes on handle 6)
2018-12-17T22:57:45.067620036Z 87 PC: 1315d | Get or set file date and time
2018-12-17T22:57:45.070493648Z 67 PC: 13116 | Get or set file attributes
2018-12-17T22:57:45.083250058Z 62 PC: 1389d | Close file
2018-12-17T22:57:45.091366876Z 53 PC: 132fc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:45.094375321Z 37 PC: 13305 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:45.096309617Z 53 PC: 132fc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:45.098262418Z 37 PC: 13305 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:45.10018914Z 53 PC: 132fc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:45.103126321Z 37 PC: 13305 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:45.104986248Z 53 PC: 132fc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:45.106945421Z 37 PC: 13305 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:45.109794616Z 53 PC: 132fc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:45.111737048Z 37 PC: 13305 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:45.113633884Z 53 PC: 132fc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:45.116370168Z 37 PC: 13305 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:45.118802109Z 53 PC: 132fc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:45.120718291Z 37 PC: 13305 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:45.123607412Z 53 PC: 132fc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:45.125436891Z 37 PC: 13305 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:45.127182463Z 53 PC: 132fc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:45.128934626Z 37 PC: 13305 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:45.131632548Z 53 PC: 132fc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:45.133369422Z 37 PC: 13305 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:45.135085348Z 53 PC: 132fc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:45.137827033Z 37 PC: 13305 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:45.139569308Z 53 PC: 132fc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:45.141317995Z 37 PC: 13305 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:45.143845736Z 53 PC: 132fc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:45.145405117Z 37 PC: 13305 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:45.147059297Z 53 PC: 132fc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:45.149430334Z 37 PC: 13305 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:45.15085891Z 53 PC: 132fc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:45.152219147Z 37 PC: 13305 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:45.153520793Z 53 PC: 132fc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:45.155422558Z 37 PC: 13305 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:45.156714847Z 53 PC: 132fc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:45.158041541Z 37 PC: 13305 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:45.161043074Z 53 PC: 132fc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:45.162388243Z 37 PC: 13305 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:45.163679961Z 53 PC: 132fc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:45.166571877Z 37 PC: 13305 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:45.168665733Z 41 PC: 132b3 | Parse filename
2018-12-17T22:57:45.170299234Z 41 PC: 132c1 | Parse filename
2018-12-17T22:57:45.172794575Z 75 PC: 132cc | Execute program
2018-12-17T22:57:45.183672634Z 53 PC: 132fc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:45.186538751Z 37 PC: 13305 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:45.188572093Z 53 PC: 132fc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:45.190025816Z 37 PC: 13305 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:45.191671009Z 53 PC: 132fc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:45.193716144Z 37 PC: 13305 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:45.195337672Z 53 PC: 132fc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:45.197151331Z 37 PC: 13305 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:45.199446896Z 53 PC: 132fc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:45.202043056Z 37 PC: 13305 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:45.203884919Z 53 PC: 132fc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:45.205574054Z 37 PC: 13305 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:45.208318152Z 53 PC: 132fc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:45.209990917Z 37 PC: 13305 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:45.211602095Z 53 PC: 132fc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:45.214425513Z 37 PC: 13305 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:45.216065326Z 53 PC: 132fc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:45.217771964Z 37 PC: 13305 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:45.220514048Z 53 PC: 132fc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:45.234780837Z 37 PC: 13305 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:45.23607525Z 53 PC: 132fc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:45.237528261Z 37 PC: 13305 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:45.240077253Z 53 PC: 132fc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:45.241572414Z 37 PC: 13305 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:45.244202408Z 53 PC: 132fc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:45.245669706Z 37 PC: 13305 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:45.247030394Z 53 PC: 132fc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:45.248414707Z 37 PC: 13305 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:45.251045582Z 53 PC: 132fc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:45.25544947Z 37 PC: 13305 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:45.258898344Z 53 PC: 132fc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:45.261574124Z 37 PC: 13305 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:45.263335264Z 53 PC: 132fc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:45.265107526Z 37 PC: 13305 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:45.267836415Z 53 PC: 132fc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:45.269611161Z 37 PC: 13305 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:45.27135006Z 53 PC: 132fc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:45.27422769Z 37 PC: 13305 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:45.275771592Z 48 PC: 1399b | Get DOS version
2018-12-17T22:57:45.277502305Z 67 PC: 13116 | Get or set file attributes
2018-12-17T22:57:45.290231694Z 61 PC: 1384d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:57:45.297678333Z 64 PC: 13920 | Write file or device (Write 5440 bytes on handle 6)
2018-12-17T22:57:45.306771776Z 66 PC: 1397f | Move file pointer
2018-12-17T22:57:45.309861515Z 64 PC: 13920 | Write file or device (Write 5440 bytes on handle 6)
2018-12-17T22:57:45.31956212Z 66 PC: 1397f | Move file pointer
2018-12-17T22:57:45.322207904Z 64 PC: 13920 | Write file or device (Write 5 bytes on handle 6)
2018-12-17T22:57:45.326891668Z 87 PC: 1315d | Get or set file date and time
2018-12-17T22:57:45.329140726Z 67 PC: 13116 | Get or set file attributes
2018-12-17T22:57:45.342059211Z 62 PC: 1389d | Close file
2018-12-17T22:57:45.351066753Z 64 PC: 137a8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:57:45.353504355Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:45.355309749Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:45.357862237Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:45.359760275Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:45.361585095Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:45.364324976Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:45.366323242Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:45.368121573Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:45.371046942Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:45.372935562Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:45.374611703Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:45.376581877Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:45.378641769Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:45.380417276Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:45.382485995Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:45.384498198Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:45.386258367Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:45.38901597Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:45.390416162Z 37 PC: 134e1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:45.39175539Z 76 PC: 13520 | Terminate with return code (Return code = '0')