Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Pepe.6810

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:39.608979813Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:39.610549328Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:39.611722817Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:39.613086246Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:39.615073262Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:39.616419898Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:39.617553439Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:39.620196422Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:39.621093032Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:39.621979392Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:39.623406558Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:39.624273481Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:39.62515562Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:39.626191877Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:39.627499007Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:39.628432534Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:39.62931319Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:39.630927408Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:39.631957262Z 53 PC: 13f0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:39.633278272Z 37 PC: 13f1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:39.635097331Z 37 PC: 13f27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:39.636271967Z 37 PC: 13f2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:39.637147878Z 37 PC: 13f37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:39.639350672Z 68 PC: 14bdc | I/O control for devices (Set for = '�')
2018-12-17T22:59:39.641147243Z 44 PC: 14d13 | Get time 0x14d13: mov word ptr [0x8a], cx
0x14d17: mov word ptr [0x8c], dx
0x14d1b: retf
0x14d1c: call 0x14d63
0x14d1f: jb 0x14d30
0x14d21: mov cx, word ptr es:[di + 4]
0x14d25: cmp cx, 1
0x14d28: je 0x14d30
0x14d2a: xor bx, bx
0x14d2c: push cs
0x14d2d: call 0x248a4
0x14d30: retf 4
0x14d33: call 0x14d63
0x14d36: jb 0x14d4b
0x14d38: mov ax, cx
0x14d3a: mov dx, bx
0x14d3c: mov cx, word ptr es:[di + 4]
0x14d40: cmp cx, 1
0x14d43: je 0x14d4b
0x14d45: xor bx, bx
2018-12-17T22:59:39.643535548Z 48 PC: 147f2 | Get DOS version
2018-12-17T22:59:39.646309888Z 67 PC: 13cdf | Get or set file attributes
2018-12-17T22:59:39.649823881Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T22:59:39.665012315Z 61 PC: 14630 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:59:39.672079185Z 63 PC: 14703 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:59:39.674807282Z 66 PC: 14762 | Move file pointer
2018-12-17T22:59:39.676155773Z 63 PC: 14703 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:59:39.683478467Z 63 PC: 14703 | Read file or device (Read 6810 bytes on handle 5)
2018-12-17T22:59:39.691136629Z 60 PC: 14630 | Create or truncate file
2018-12-17T22:59:39.701975543Z 63 PC: 14703 | Read file or device (Read 10000 bytes on handle 5)
2018-12-17T22:59:39.704529418Z 66 PC: 14d7d | Move file pointer
2018-12-17T22:59:39.705945305Z 66 PC: 14d8b | Move file pointer
2018-12-17T22:59:39.707299088Z 66 PC: 14d99 | Move file pointer
2018-12-17T22:59:39.710525523Z 62 PC: 14680 | Close file
2018-12-17T22:59:39.712340434Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T22:59:39.722508862Z 62 PC: 14680 | Close file
2018-12-17T22:59:39.725244237Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:39.72648427Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:39.727836411Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:39.729712317Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:39.730749568Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:39.731771344Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:39.733231371Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:39.734299848Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:39.735210892Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:39.737836721Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:39.738931622Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:39.740027467Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:39.742073747Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:39.743342305Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:39.744524689Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:39.746795459Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:39.748168667Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:39.749642115Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:39.751258902Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:39.75298915Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:39.754027254Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:39.755092173Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:39.756492936Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:39.757682086Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:39.758809796Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:39.760027854Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:39.761183513Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:39.762257602Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:39.764169482Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:39.765705326Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:39.767169679Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:39.769666254Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:39.771137005Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:39.772645672Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:39.774964817Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:39.776185001Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:39.777418043Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:39.779752381Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:39.781330619Z 41 PC: 13e35 | Parse filename
2018-12-17T22:59:39.782925298Z 41 PC: 13e43 | Parse filename
2018-12-17T22:59:39.785058281Z 75 PC: 13e4e | Execute program
2018-12-17T22:59:39.79356356Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:39.794963201Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:39.796932986Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:39.798088492Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:39.799146509Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:39.803213187Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:39.804497961Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:39.805610948Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:39.808746799Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:39.810214162Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:39.811919169Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:39.813776311Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:39.815137426Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:39.816447955Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:39.818601933Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:39.819824056Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:39.820999004Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:39.82284013Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:39.824600732Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:39.825720732Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:39.82749179Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:39.829068362Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:39.830620966Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:39.833034137Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:39.834508966Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:39.835821423Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:39.838417549Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:39.839530118Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:39.840567366Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:39.841815098Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:39.843278464Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:39.844529354Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:39.845955229Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:39.847643013Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:39.848563821Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:39.849433768Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:39.850963158Z 53 PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:39.852218062Z 37 PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:39.853609994Z 65 PC: 14779 | Delete file (Filename = 'Victim.Exe')
2018-12-17T22:59:39.880212074Z 26 PC: 13d7d | Set disk transfer address
2018-12-17T22:59:39.881355286Z 78 PC: 13d89 | Find first file
2018-12-17T22:59:39.887485418Z 86 PC: 147bd | Rename file
2018-12-17T22:59:39.902366205Z 60 PC: 14630 | Create or truncate file
2018-12-17T22:59:39.913936075Z 67 PC: 13cdf | Get or set file attributes
2018-12-17T22:59:39.920140558Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T22:59:39.930321586Z 61 PC: 14630 | Open file (Filename = 'Victim.Exe')
2018-12-17T22:59:39.936843457Z 64 PC: 14703 | Write file or device (Write 7091 bytes on handle 5)
2018-12-17T22:59:39.945278516Z 64 PC: 14703 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:59:39.949383362Z 64 PC: 14703 | Write file or device (Write 6810 bytes on handle 5)
2018-12-17T22:59:39.958817643Z 63 PC: 14703 | Read file or device (Read 10000 bytes on handle 6)
2018-12-17T22:59:39.967349476Z 64 PC: 14703 | Write file or device (Write 10000 bytes on handle 5)
2018-12-17T22:59:39.97562751Z 66 PC: 14d7d | Move file pointer
2018-12-17T22:59:39.976684303Z 66 PC: 14d8b | Move file pointer
2018-12-17T22:59:39.977732978Z 66 PC: 14d99 | Move file pointer
2018-12-17T22:59:39.979450785Z 63 PC: 14703 | Read file or device (Read 10000 bytes on handle 6)
2018-12-17T22:59:39.983911408Z 64 PC: 14703 | Write file or device (Write 3029 bytes on handle 5)
2018-12-17T22:59:39.98957652Z 66 PC: 14d7d | Move file pointer
2018-12-17T22:59:39.991357925Z 66 PC: 14d8b | Move file pointer
2018-12-17T22:59:39.992324061Z 66 PC: 14d99 | Move file pointer
2018-12-17T22:59:39.993646314Z 87 PC: 13d4d | Get or set file date and time
2018-12-17T22:59:39.995252589Z 62 PC: 14680 | Close file
2018-12-17T22:59:39.996508209Z 67 PC: 13d06 | Get or set file attributes
2018-12-17T22:59:40.003356675Z 62 PC: 14680 | Close file
2018-12-17T22:59:40.008382022Z 65 PC: 14779 | Delete file (Filename = 'Victim.Exe')
2018-12-17T22:59:40.015795113Z 26 PC: 13da1 | Set disk transfer address
2018-12-17T22:59:40.016635039Z 79 PC: 13da6 | Find next file
2018-12-17T22:59:40.019011939Z 26 PC: 13da1 | Set disk transfer address
2018-12-17T22:59:40.019859427Z 79 PC: 13da6 | Find next file
2018-12-17T22:59:40.022017724Z 64 PC: 1458b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:59:40.02360782Z 37 PC: 14061 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:40.024478336Z 37 PC: 14061 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:40.025942664Z 37 PC: 14061 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:40.026849342Z 37 PC: 14061 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:40.027713725Z 37 PC: 14061 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:40.029099947Z 37 PC: 14061 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:40.029972403Z 37 PC: 14061 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:40.030848354Z 37 PC: 14061 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:40.032292444Z 37 PC: 14061 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:40.033168618Z 37 PC: 14061 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:40.0340358Z 37 PC: 14061 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:40.035439715Z 37 PC: 14061 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:40.03685814Z 37 PC: 14061 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:40.037722662Z 37 PC: 14061 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:40.039168393Z 37 PC: 14061 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:40.040268227Z 37 PC: 14061 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:40.041276012Z 37 PC: 14061 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:40.042789317Z 37 PC: 14061 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:40.043692206Z 37 PC: 14061 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:40.044603942Z 76 PC: 140a0 | Terminate with return code (Return code = '0')