Sample viewer

vx.netlux.org/Virus.DOS.HLLP.4274

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:55.801252389Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:55.804291373Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:55.80560847Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:55.814964511Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:55.817816138Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:55.819284568Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:55.820685977Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:55.822919223Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:55.824667695Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:55.826113418Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:55.827802564Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:55.829973892Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:55.831385721Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:55.832793434Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:55.849814186Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:55.851230119Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:55.852636915Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:55.858277088Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:55.860478961Z 53 PC: 12f9e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:55.864084389Z 37 PC: 12fb3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:55.866598988Z 37 PC: 12fba | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:55.867707862Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:55.868776875Z 37 PC: 12fc8 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:55.871730029Z 68 PC: 13349 | I/O control for devices (Set for = '')
2018-12-17T22:58:55.873699686Z 48 PC: 1382b | Get DOS version
2018-12-17T22:58:55.875292983Z 61 PC: 136d1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:58:55.883364111Z 63 PC: 137b0 | Read file or device (Read 4273 bytes on handle 5)
2018-12-17T22:58:55.891158314Z 66 PC: 13452 | Move file pointer
2018-12-17T22:58:55.892789043Z 66 PC: 13460 | Move file pointer
2018-12-17T22:58:55.895606821Z 66 PC: 1346e | Move file pointer
2018-12-17T22:58:55.897079821Z 66 PC: 13452 | Move file pointer
2018-12-17T22:58:55.898964035Z 66 PC: 13460 | Move file pointer
2018-12-17T22:58:55.902917425Z 66 PC: 1346e | Move file pointer
2018-12-17T22:58:55.904670104Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:55.906157622Z 64 PC: 13704 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:58:55.919808453Z 66 PC: 13452 | Move file pointer
2018-12-17T22:58:55.92154244Z 66 PC: 13460 | Move file pointer
2018-12-17T22:58:55.923249375Z 66 PC: 1346e | Move file pointer
2018-12-17T22:58:55.925935092Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:55.927644157Z 63 PC: 137b0 | Read file or device (Read 4273 bytes on handle 5)
2018-12-17T22:58:55.935554718Z 64 PC: 13704 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:58:55.958771756Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:55.960769671Z 64 PC: 137b0 | Write file or device (Write 4273 bytes on handle 5)
2018-12-17T22:58:55.966353594Z 62 PC: 13723 | Close file
2018-12-17T22:58:55.973901027Z 48 PC: 1382b | Get DOS version
2018-12-17T22:58:55.977383296Z 41 PC: 12ee1 | Parse filename
2018-12-17T22:58:55.979178819Z 41 PC: 12eef | Parse filename
2018-12-17T22:58:55.98085696Z 75 PC: 12efa | Execute program
2018-12-17T22:58:55.996792888Z 53 PC: 19052 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:55.998267551Z 53 PC: 19052 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:55.999702268Z 53 PC: 19052 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:56.001878046Z 53 PC: 19052 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:56.003436771Z 53 PC: 19052 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:56.005069861Z 53 PC: 19052 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:56.007304283Z 53 PC: 19052 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:56.008797325Z 53 PC: 19052 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:56.010509438Z 53 PC: 19052 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:56.012775951Z 53 PC: 19052 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:56.014301223Z 53 PC: 19052 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:56.015635032Z 53 PC: 19052 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:56.017203881Z 53 PC: 19052 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:56.018857306Z 53 PC: 19052 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:56.020151312Z 53 PC: 19052 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:56.021997222Z 53 PC: 19052 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:56.023692771Z 53 PC: 19052 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:56.025447371Z 53 PC: 19052 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:56.027443313Z 53 PC: 19052 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:56.029068662Z 37 PC: 19067 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:56.030740654Z 37 PC: 1906f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:56.033206034Z 37 PC: 19077 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:56.036269452Z 37 PC: 1907f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:56.038150343Z 68 PC: 193ef | I/O control for devices (Set for = '')
2018-12-17T22:58:56.113780348Z 37 PC: 18a75 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:56.11849333Z 58 PC: 19efa | Remove subdirectory
2018-12-17T22:58:56.128261453Z 25 PC: 19e33 | Get default drive
2018-12-17T22:58:56.13000359Z 71 PC: 19e46 | Get current directory
2018-12-17T22:58:56.134033565Z 59 PC: 19efa | Change current directory
2018-12-17T22:58:56.140434764Z 14 PC: 19e8c | Set default drive (Drive = 'A')
2018-12-17T22:58:56.142271078Z 25 PC: 19e90 | Get default drive
2018-12-17T22:58:56.144102561Z 59 PC: 19efa | Change current directory
2018-12-17T22:58:56.33423317Z 54 PC: 1896a | Get free disk space
2018-12-17T22:58:56.344677873Z 67 PC: 189ca | Get or set file attributes
2018-12-17T22:58:56.350751669Z 60 PC: 19c7a | Create or truncate file
2018-12-17T22:58:56.716737287Z 62 PC: 19cca | Close file
2018-12-17T22:58:56.719402108Z 65 PC: 19dc3 | Delete file (Filename = 'C:\mempatch.exe')
2018-12-17T22:58:56.730394764Z 37 PC: 19166 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:56.732056596Z 37 PC: 19166 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:56.733668044Z 37 PC: 19166 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:56.735840587Z 37 PC: 19166 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:56.737494837Z 37 PC: 19166 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:56.739099417Z 37 PC: 19166 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:56.741692494Z 37 PC: 19166 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:56.743294842Z 37 PC: 19166 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:56.74487781Z 37 PC: 19166 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:56.747452338Z 37 PC: 19166 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:56.749007971Z 37 PC: 19166 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:56.750557368Z 37 PC: 19166 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:56.7529865Z 37 PC: 19166 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:56.754948067Z 37 PC: 19166 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:56.756361715Z 37 PC: 19166 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:56.758644415Z 37 PC: 19166 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:56.760346753Z 37 PC: 19166 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:56.761688061Z 37 PC: 19166 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:56.763789355Z 37 PC: 19166 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:56.765523945Z 76 PC: 191a5 | Terminate with return code (Return code = '0')
2018-12-17T22:58:56.768809966Z 26 PC: 12db5 | Set disk transfer address
2018-12-17T22:58:56.770967527Z 78 PC: 12dc1 | Find first file
2018-12-17T22:58:56.778403556Z 61 PC: 136d1 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:58:56.78515216Z 66 PC: 13452 | Move file pointer
2018-12-17T22:58:56.786959976Z 66 PC: 13460 | Move file pointer
2018-12-17T22:58:56.789421055Z 66 PC: 1346e | Move file pointer
2018-12-17T22:58:56.791148473Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:56.792878419Z 63 PC: 137b0 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:58:56.797127186Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:56.798859658Z 63 PC: 137b0 | Read file or device (Read 4273 bytes on handle 5)
2018-12-17T22:58:56.806253052Z 66 PC: 13452 | Move file pointer
2018-12-17T22:58:56.808789918Z 66 PC: 13460 | Move file pointer
2018-12-17T22:58:56.810418377Z 66 PC: 1346e | Move file pointer
2018-12-17T22:58:56.812113523Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:56.814808112Z 64 PC: 137b0 | Write file or device (Write 4273 bytes on handle 5)
2018-12-17T22:58:56.823552356Z 64 PC: 137b0 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:58:56.826556509Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:56.829071415Z 64 PC: 137b0 | Write file or device (Write 4273 bytes on handle 5)
2018-12-17T22:58:56.842661498Z 62 PC: 13723 | Close file
2018-12-17T22:58:56.8513218Z 26 PC: 12ddb | Set disk transfer address
2018-12-17T22:58:56.853352747Z 79 PC: 12de0 | Find next file
2018-12-17T22:58:56.856592605Z 59 PC: 1398c | Change current directory
2018-12-17T22:58:56.861042478Z 26 PC: 12db5 | Set disk transfer address
2018-12-17T22:58:56.863359661Z 78 PC: 12dc1 | Find first file
2018-12-17T22:58:56.869870534Z 61 PC: 136d1 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:58:56.876703273Z 66 PC: 13452 | Move file pointer
2018-12-17T22:58:56.87877858Z 66 PC: 13460 | Move file pointer
2018-12-17T22:58:56.880613813Z 66 PC: 1346e | Move file pointer
2018-12-17T22:58:56.882350057Z 66 PC: 1380f | Move file pointer
2018-12-17T22:58:56.88465412Z 63 PC: 137b0 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:58:56.887909627Z 26 PC: 12ddb | Set disk transfer address
2018-12-17T22:58:56.889216082Z 79 PC: 12de0 | Find next file
2018-12-17T22:58:56.892431252Z 64 PC: 13628 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:58:56.894192931Z 37 PC: 13107 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:56.895313952Z 37 PC: 13107 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:56.897091905Z 37 PC: 13107 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:56.898612347Z 37 PC: 13107 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:56.900189179Z 37 PC: 13107 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:56.90149399Z 37 PC: 13107 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:56.903222852Z 37 PC: 13107 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:56.904334279Z 37 PC: 13107 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:56.905405581Z 37 PC: 13107 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:56.907192294Z 37 PC: 13107 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:56.908257752Z 37 PC: 13107 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:56.909400298Z 37 PC: 13107 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:56.911497633Z 37 PC: 13107 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:56.912979965Z 37 PC: 13107 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:56.914096386Z 37 PC: 13107 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:56.916229369Z 37 PC: 13107 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:56.917457238Z 37 PC: 13107 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:56.918462645Z 37 PC: 13107 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:56.920885679Z 37 PC: 13107 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:56.921874898Z 76 PC: 13146 | Terminate with return code (Return code = '0')