Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Dupalec.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:41.842599421Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:41.844066658Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:41.845473667Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:59:41.846661678Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:41.847930898Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:41.850241555Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:41.851406334Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:41.852542373Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:41.854565858Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:41.85603704Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:41.857475416Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:41.865264643Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:41.866953094Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:41.868601726Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:41.870840898Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:41.872299675Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:41.873693975Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:41.875282888Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:41.877258473Z 53 PC: 13ae2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:59:41.879006418Z 37 PC: 13af7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:41.880550321Z 37 PC: 13aff | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:41.882712702Z 37 PC: 13b07 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:41.884226072Z 37 PC: 13b0f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:59:41.886368901Z 68 PC: 13e7f | I/O control for devices (Set for = '')
2018-12-17T22:59:41.888853443Z 48 PC: 1451c | Get DOS version
2018-12-17T22:59:41.891487293Z 57 PC: 14670 | Create subdirectory
2018-12-17T22:59:41.915267881Z 58 PC: 14670 | Remove subdirectory
2018-12-17T22:59:41.930846783Z 26 PC: 1377d | Set disk transfer address
2018-12-17T22:59:41.932005304Z 78 PC: 13789 | Find first file
2018-12-17T22:59:41.938755568Z 25 PC: 13917 | Get default drive
2018-12-17T22:59:41.940844357Z 71 PC: 13936 | Get current directory
2018-12-17T22:59:41.944323437Z 26 PC: 137a1 | Set disk transfer address
2018-12-17T22:59:41.945440123Z 79 PC: 137a6 | Find next file
2018-12-17T22:59:41.952944038Z 26 PC: 1377d | Set disk transfer address
2018-12-17T22:59:41.954191092Z 78 PC: 13789 | Find first file
2018-12-17T22:59:41.966918125Z 25 PC: 13917 | Get default drive
2018-12-17T22:59:41.968549803Z 71 PC: 13936 | Get current directory
2018-12-17T22:59:41.985688651Z 25 PC: 13917 | Get default drive
2018-12-17T22:59:41.987230244Z 71 PC: 13936 | Get current directory
2018-12-17T22:59:41.991577462Z 41 PC: 138b0 | Parse filename
2018-12-17T22:59:41.993282979Z 41 PC: 138be | Parse filename
2018-12-17T22:59:41.994782055Z 75 PC: 138c9 | Execute program
2018-12-17T22:59:42.018441616Z 80 PC: 18a79 | Set current PSP
2018-12-17T22:59:42.020293917Z 48 PC: 18a7e | Get DOS version
2018-12-17T22:59:42.021909065Z 99 PC: 1f260 | Get DBCS lead byte table pointer
2018-12-17T22:59:42.024663041Z 101 PC: 18b04 | Get extended country info
2018-12-17T22:59:42.026265299Z 99 PC: 18b0a | Get DBCS lead byte table pointer
2018-12-17T22:59:42.027257383Z 74 PC: 18b6c | Reallocate memory
2018-12-17T22:59:42.028222945Z 25 PC: 18ba3 | Get default drive
2018-12-17T22:59:42.029462086Z 37 PC: 18663 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:59:42.03065135Z 37 PC: 1866a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:42.031610551Z 37 PC: 18671 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:42.03486701Z 74 PC: 1780c | Reallocate memory
2018-12-17T22:59:42.036088815Z 72 PC: 1784d | Allocate memory
2018-12-17T22:59:42.037279095Z 72 PC: 17885 | Allocate memory
2018-12-17T22:59:42.039370713Z 72 PC: 1788d | Allocate memory