Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Smoller.70440

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:10.728939594Z 53 PC: 149ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:10.732222553Z 53 PC: 149ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:10.733856474Z 53 PC: 149ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:10.735500152Z 53 PC: 149ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:10.738236073Z 53 PC: 149ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:10.740103803Z 53 PC: 149ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:10.742013211Z 53 PC: 149ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:10.744851395Z 53 PC: 149ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:10.746457333Z 53 PC: 149ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:10.74810538Z 53 PC: 149ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:10.750751413Z 53 PC: 149ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:10.752537279Z 53 PC: 149ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:10.754408475Z 53 PC: 149ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:10.757120772Z 53 PC: 149ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:10.765478729Z 53 PC: 149ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:10.767048749Z 53 PC: 149ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:10.768744146Z 53 PC: 149ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:10.771164855Z 53 PC: 149ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:10.7726685Z 53 PC: 149ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:10.774130057Z 37 PC: 149df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:10.778478348Z 37 PC: 149e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:10.779896984Z 37 PC: 149ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:10.781050151Z 37 PC: 149f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:10.783504303Z 68 PC: 15935 | I/O control for devices (Set for = 'T��Bu��[i')
2018-12-17T23:00:10.862463566Z 37 PC: 143f1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:10.864665804Z 48 PC: 15546 | Get DOS version
2018-12-17T23:00:10.867236334Z 48 PC: 15546 | Get DOS version
2018-12-17T23:00:10.86878258Z 61 PC: 15384 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:10.87589154Z 66 PC: 15ad6 | Move file pointer
2018-12-17T23:00:10.878398892Z 66 PC: 15ae4 | Move file pointer
2018-12-17T23:00:10.880386216Z 66 PC: 15af2 | Move file pointer
2018-12-17T23:00:10.882467438Z 62 PC: 153d4 | Close file
2018-12-17T23:00:10.886852899Z 26 PC: 14189 | Set disk transfer address
2018-12-17T23:00:10.888556611Z 78 PC: 14195 | Find first file
2018-12-17T23:00:10.896284964Z 61 PC: 15384 | Open file (Filename = 'TEST.com')
2018-12-17T23:00:10.904635516Z 48 PC: 15546 | Get DOS version
2018-12-17T23:00:10.906966517Z 41 PC: 14313 | Parse filename
2018-12-17T23:00:10.908833906Z 41 PC: 14321 | Parse filename
2018-12-17T23:00:10.910912803Z 75 PC: 1432c | Execute program
2018-12-17T23:00:10.936028061Z 80 PC: 3f459 | Set current PSP
2018-12-17T23:00:10.937180015Z 48 PC: 3f45e | Get DOS version
2018-12-17T23:00:10.939096587Z 99 PC: 45c40 | Get DBCS lead byte table pointer
2018-12-17T23:00:10.942141209Z 101 PC: 3f4e4 | Get extended country info
2018-12-17T23:00:10.943500633Z 99 PC: 3f4ea | Get DBCS lead byte table pointer
2018-12-17T23:00:10.945066857Z 74 PC: 3f54c | Reallocate memory
2018-12-17T23:00:10.947057267Z 25 PC: 3f583 | Get default drive
2018-12-17T23:00:10.948540935Z 37 PC: 3f043 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:00:10.950094634Z 37 PC: 3f04a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:10.951730268Z 37 PC: 3f051 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:10.956121911Z 74 PC: 3e1ec | Reallocate memory
2018-12-17T23:00:10.957632921Z 72 PC: 3e22d | Allocate memory
2018-12-17T23:00:10.95983575Z 72 PC: 3e265 | Allocate memory
2018-12-17T23:00:10.96193241Z 72 PC: 3e26d | Allocate memory