Sample viewer

vx.netlux.org/Virus.DOS.HLL.Bigbody

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:15.062727807Z 53 PC: 13132 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:15.065120661Z 53 PC: 13132 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:15.066864767Z 53 PC: 13132 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:15.068717069Z 53 PC: 13132 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:15.070588312Z 53 PC: 13132 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:15.074936426Z 53 PC: 13132 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:15.076774918Z 53 PC: 13132 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:15.078520451Z 53 PC: 13132 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:15.082161496Z 53 PC: 13132 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:15.083729649Z 53 PC: 13132 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:15.085270516Z 53 PC: 13132 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:15.088242666Z 53 PC: 13132 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:15.089995765Z 53 PC: 13132 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:15.091783271Z 53 PC: 13132 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:15.094650977Z 53 PC: 13132 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:15.096162059Z 53 PC: 13132 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:15.097636419Z 53 PC: 13132 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:15.099403644Z 53 PC: 13132 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:15.102520529Z 53 PC: 13132 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:15.105010256Z 37 PC: 13147 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:15.107095034Z 37 PC: 1314f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:15.111127457Z 37 PC: 13157 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:15.112948061Z 37 PC: 1315f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:15.115287443Z 68 PC: 13732 | I/O control for devices (Set for = '')
2018-12-17T23:00:15.119689734Z 48 PC: 14110 | Get DOS version
2018-12-17T23:00:15.121787076Z 61 PC: 13ed0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:15.131437763Z 63 PC: 13fa3 | Read file or device (Read 4859 bytes on handle 5)
2018-12-17T23:00:15.146341803Z 66 PC: 14002 | Move file pointer
2018-12-17T23:00:15.148894817Z 66 PC: 1406c | Move file pointer
2018-12-17T23:00:15.151127315Z 66 PC: 1407a | Move file pointer
2018-12-17T23:00:15.154708979Z 66 PC: 14088 | Move file pointer
2018-12-17T23:00:15.158367612Z 63 PC: 13fa3 | Read file or device (Read 1605 bytes on handle 5)
2018-12-17T23:00:15.167053119Z 60 PC: 13ed0 | Create or truncate file
2018-12-17T23:00:15.186848883Z 64 PC: 13fa3 | Write file or device (Write 1605 bytes on handle 6)
2018-12-17T23:00:15.19982261Z 62 PC: 13f20 | Close file
2018-12-17T23:00:15.206022641Z 62 PC: 13f20 | Close file
2018-12-17T23:00:15.217766491Z 53 PC: 1301c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:15.22028995Z 37 PC: 13025 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:15.224693191Z 53 PC: 1301c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:15.226895876Z 37 PC: 13025 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:15.229953449Z 53 PC: 1301c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:15.231287805Z 37 PC: 13025 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:15.232567672Z 53 PC: 1301c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:15.234356712Z 37 PC: 13025 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:15.235663585Z 53 PC: 1301c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:15.236968916Z 37 PC: 13025 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:15.238691171Z 53 PC: 1301c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:15.242807688Z 37 PC: 13025 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:15.246551312Z 53 PC: 1301c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:15.248864532Z 37 PC: 13025 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:15.253710842Z 53 PC: 1301c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:15.255178062Z 37 PC: 13025 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:15.257620826Z 53 PC: 1301c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:15.259993564Z 37 PC: 13025 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:15.265582526Z 53 PC: 1301c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:15.266954885Z 37 PC: 13025 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:15.271163775Z 53 PC: 1301c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:15.272864295Z 37 PC: 13025 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:15.274487519Z 53 PC: 1301c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:15.277029075Z 37 PC: 13025 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:15.279020863Z 53 PC: 1301c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:15.28094883Z 37 PC: 13025 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:15.283587094Z 53 PC: 1301c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:15.285070802Z 37 PC: 13025 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:15.286515261Z 53 PC: 1301c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:15.288761423Z 37 PC: 13025 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:15.290840227Z 53 PC: 1301c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:15.293304162Z 37 PC: 13025 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:15.295943622Z 53 PC: 1301c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:15.298102364Z 37 PC: 13025 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:15.299996843Z 53 PC: 1301c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:15.301677602Z 37 PC: 13025 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:15.30436591Z 53 PC: 1301c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:15.306042597Z 37 PC: 13025 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:15.307990288Z 41 PC: 130a5 | Parse filename
2018-12-17T23:00:15.310801225Z 41 PC: 130b3 | Parse filename
2018-12-17T23:00:15.312880906Z 75 PC: 130be | Execute program