Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Xenia.5809

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:03.772768324Z 74 PC: 14522 | Reallocate memory
2018-12-17T23:00:03.776065906Z 53 PC: 1337a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:03.777272332Z 53 PC: 1337a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:03.778508602Z 53 PC: 1337a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:03.780148177Z 53 PC: 1337a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:03.782106962Z 53 PC: 1337a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:03.783183508Z 53 PC: 1337a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:03.784266176Z 53 PC: 1337a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:03.786475216Z 53 PC: 1337a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:03.787543508Z 53 PC: 1337a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:03.788621964Z 53 PC: 1337a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:03.790930197Z 53 PC: 1337a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:03.792929202Z 53 PC: 1337a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:03.794957735Z 53 PC: 1337a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:03.797356141Z 53 PC: 1337a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:03.798713458Z 53 PC: 1337a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:03.800067095Z 53 PC: 1337a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:03.801713508Z 53 PC: 1337a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:03.803683482Z 53 PC: 1337a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:03.805402166Z 53 PC: 1337a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:03.806760145Z 37 PC: 1338f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:03.80849489Z 37 PC: 13397 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:03.809998662Z 37 PC: 1339f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:03.810943364Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:03.812902141Z 68 PC: 14335 | I/O control for devices (Set for = '')
2018-12-17T23:00:03.814779526Z 48 PC: 13e65 | Get DOS version
2018-12-17T23:00:03.816368396Z 61 PC: 13ca3 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T23:00:03.823642704Z 60 PC: 13ca3 | Create or truncate file
2018-12-17T23:00:03.842508224Z 63 PC: 13d76 | Read file or device (Read 5809 bytes on handle 5)
2018-12-17T23:00:03.850693089Z 66 PC: 13dd5 | Move file pointer
2018-12-17T23:00:03.852705961Z 66 PC: 14434 | Move file pointer
2018-12-17T23:00:03.854297272Z 66 PC: 14442 | Move file pointer
2018-12-17T23:00:03.85601564Z 66 PC: 14450 | Move file pointer
2018-12-17T23:00:03.858218921Z 63 PC: 13d76 | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:00:03.866160076Z 64 PC: 13d76 | Write file or device (Write 1754 bytes on handle 6)
2018-12-17T23:00:03.874347529Z 66 PC: 14434 | Move file pointer
2018-12-17T23:00:03.876379012Z 66 PC: 14442 | Move file pointer
2018-12-17T23:00:03.878038873Z 66 PC: 14450 | Move file pointer
2018-12-17T23:00:03.879778974Z 62 PC: 13cf3 | Close file
2018-12-17T23:00:03.888244237Z 62 PC: 13cf3 | Close file
2018-12-17T23:00:03.890774907Z 41 PC: 1327f | Parse filename
2018-12-17T23:00:03.892293868Z 41 PC: 1328d | Parse filename
2018-12-17T23:00:03.894190434Z 75 PC: 13298 | Execute program
2018-12-17T23:00:03.909321256Z 48 PC: 1915c | Get DOS version
2018-12-17T23:00:03.910694422Z 101 PC: 1917d | Get extended country info
2018-12-17T23:00:03.913534686Z 2 PC: 1932a | Character output (Char = '5b')
2018-12-17T23:00:03.916072419Z 2 PC: 19330 | Character output (Char = '59')
2018-12-17T23:00:03.918234953Z 2 PC: 1933c | Character output (Char = '2c')
2018-12-17T23:00:03.920497101Z 2 PC: 19330 | Character output (Char = '4e')
2018-12-17T23:00:03.923023868Z 2 PC: 19344 | Character output (Char = '5d')
2018-12-17T23:00:03.925880373Z 2 PC: 1934a | Character output (Char = '3f')
2018-12-17T23:00:03.928031268Z 8 PC: 19382 | Console input without echo