Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Brian.4709.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:18.938689679Z 53 PC: 131ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:18.941222265Z 53 PC: 131ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:18.947480498Z 53 PC: 131ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:18.948673268Z 53 PC: 131ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:18.950388329Z 53 PC: 131ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:18.951913372Z 53 PC: 131ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:18.95373521Z 53 PC: 131ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:18.955890493Z 53 PC: 131ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:18.957321889Z 53 PC: 131ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:18.958528548Z 53 PC: 131ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:18.960362506Z 53 PC: 131ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:18.961839342Z 53 PC: 131ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:18.963250593Z 53 PC: 131ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:18.964556895Z 53 PC: 131ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:18.966186221Z 53 PC: 131ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:18.96757546Z 53 PC: 131ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:18.968964439Z 53 PC: 131ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:18.970870272Z 53 PC: 131ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:18.972125382Z 53 PC: 131ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:18.973531028Z 37 PC: 131cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:18.975158706Z 37 PC: 131d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:18.976224107Z 37 PC: 131df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:18.977277992Z 37 PC: 131e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:18.979756404Z 68 PC: 13a45 | I/O control for devices (Set for = '')
2018-12-17T23:00:18.981868799Z 42 PC: 12f68 | Get date 0x12f68: mov byte ptr [0x56], dh
0x12f6c: mov byte ptr [0x57], dl
0x12f70: mov di, 0x59
0x12f73: push ds
0x12f74: push di
0x12f75: call 0x22a40
0x12f78: cmp byte ptr [0x57], 0xb
0x12f7d: mov al, 0
0x12f7f: jne 0x12f82
0x12f81: inc ax
0x12f82: mov dl, al
0x12f84: cmp byte ptr [0x56], 9
0x12f89: mov al, 0
0x12f8b: jne 0x12f8e
0x12f8d: inc ax
0x12f8e: and al, dl
0x12f90: or al, al
0x12f92: je 0x12fa2
0x12f94: mov ah, 0x40
0x12f96: mov bx, 1
2018-12-17T23:00:18.984655574Z 48 PC: 13770 | Get DOS version
2018-12-17T23:00:18.987552638Z 48 PC: 13770 | Get DOS version
2018-12-17T23:00:18.989265321Z 61 PC: 13622 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:18.997028297Z 63 PC: 136f5 | Read file or device (Read 4704 bytes on handle 5)
2018-12-17T23:00:19.005708927Z 62 PC: 13672 | Close file
2018-12-17T23:00:19.008119159Z 26 PC: 13037 | Set disk transfer address
2018-12-17T23:00:19.009484767Z 78 PC: 13043 | Find first file
2018-12-17T23:00:19.016555108Z 61 PC: 13622 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:00:19.022805204Z 66 PC: 13754 | Move file pointer
2018-12-17T23:00:19.024434359Z 63 PC: 136f5 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T23:00:19.031973479Z 26 PC: 1305b | Set disk transfer address
2018-12-17T23:00:19.033291046Z 79 PC: 13060 | Find next file
2018-12-17T23:00:19.036604044Z 48 PC: 13770 | Get DOS version
2018-12-17T23:00:19.039354396Z 26 PC: 13037 | Set disk transfer address
2018-12-17T23:00:19.040397062Z 78 PC: 13043 | Find first file
2018-12-17T23:00:19.047883188Z 48 PC: 13770 | Get DOS version
2018-12-17T23:00:19.050195932Z 67 PC: 13006 | Get or set file attributes
2018-12-17T23:00:19.068246138Z 61 PC: 13622 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:19.074779337Z 66 PC: 13754 | Move file pointer
2018-12-17T23:00:19.076902416Z 63 PC: 136f5 | Read file or device (Read 4704 bytes on handle 6)
2018-12-17T23:00:19.084834719Z 66 PC: 13754 | Move file pointer
2018-12-17T23:00:19.086283411Z 64 PC: 13653 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:00:19.09399401Z 66 PC: 13754 | Move file pointer
2018-12-17T23:00:19.095967726Z 64 PC: 136f5 | Write file or device (Write 4704 bytes on handle 6)
2018-12-17T23:00:19.103500794Z 62 PC: 13672 | Close file
2018-12-17T23:00:19.110978069Z 53 PC: 13138 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:19.113000876Z 37 PC: 13141 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:19.11411776Z 53 PC: 13138 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:19.11548352Z 37 PC: 13141 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:19.117021213Z 53 PC: 13138 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:19.118360336Z 37 PC: 13141 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:19.12054937Z 53 PC: 13138 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:19.122018233Z 37 PC: 13141 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:19.123153036Z 53 PC: 13138 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:19.124734302Z 37 PC: 13141 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:19.125729496Z 53 PC: 13138 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:19.126675589Z 37 PC: 13141 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:19.128166676Z 53 PC: 13138 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:19.129143443Z 37 PC: 13141 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:19.130044111Z 53 PC: 13138 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:19.131502116Z 37 PC: 13141 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:19.132424433Z 53 PC: 13138 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:19.133526726Z 37 PC: 13141 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:19.136129035Z 53 PC: 13138 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:19.137245352Z 37 PC: 13141 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:19.138206504Z 53 PC: 13138 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:19.139768111Z 37 PC: 13141 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:19.140707698Z 53 PC: 13138 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:19.141644423Z 37 PC: 13141 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:19.143079473Z 53 PC: 13138 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:19.144104081Z 37 PC: 13141 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:19.145002221Z 53 PC: 13138 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:19.14663142Z 37 PC: 13141 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:19.147619527Z 53 PC: 13138 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:19.148701827Z 37 PC: 13141 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:19.150115972Z 53 PC: 13138 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:19.151097391Z 37 PC: 13141 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:19.152010784Z 53 PC: 13138 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:19.153549924Z 37 PC: 13141 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:19.154467378Z 53 PC: 13138 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:19.155314425Z 37 PC: 13141 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:19.156887216Z 53 PC: 13138 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:19.157899697Z 37 PC: 13141 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:19.159311605Z 41 PC: 130ef | Parse filename
2018-12-17T23:00:19.161180513Z 41 PC: 130fd | Parse filename
2018-12-17T23:00:19.162387954Z 75 PC: 13108 | Execute program
2018-12-17T23:00:19.176931474Z 9 PC: 171d8 | Display string (Could not find end pointer)
2018-12-17T23:00:19.191801341Z 76 PC: 171dc | Terminate with return code (Return code = '36')
2018-12-17T23:00:19.194488059Z 53 PC: 13138 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:19.195467642Z 37 PC: 13141 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:19.196602139Z 53 PC: 13138 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:19.197836587Z 37 PC: 13141 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:19.199127946Z 53 PC: 13138 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:19.200303988Z 37 PC: 13141 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:19.20150097Z 53 PC: 13138 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:19.202461761Z 37 PC: 13141 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:19.203560509Z 53 PC: 13138 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:19.204730479Z 37 PC: 13141 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:19.205681447Z 53 PC: 13138 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:19.206804884Z 37 PC: 13141 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:19.207832064Z 53 PC: 13138 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:19.208778717Z 37 PC: 13141 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:19.209877899Z 53 PC: 13138 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:19.211021194Z 37 PC: 13141 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:19.212084644Z 53 PC: 13138 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:19.213197707Z 37 PC: 13141 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:19.215194845Z 53 PC: 13138 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:19.216413263Z 37 PC: 13141 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:19.217635426Z 53 PC: 13138 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:19.218876334Z 37 PC: 13141 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:19.219880021Z 53 PC: 13138 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:19.221121123Z 37 PC: 13141 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:19.222260877Z 53 PC: 13138 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:19.223449666Z 37 PC: 13141 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:19.224495526Z 53 PC: 13138 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:19.225925439Z 37 PC: 13141 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:19.227069519Z 53 PC: 13138 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:19.228433052Z 37 PC: 13141 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:19.23437272Z 53 PC: 13138 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:19.235748142Z 37 PC: 13141 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:19.237099817Z 53 PC: 13138 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:19.239974908Z 37 PC: 13141 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:19.241483967Z 53 PC: 13138 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:19.242824654Z 37 PC: 13141 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:19.245026504Z 53 PC: 13138 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:19.246402253Z 37 PC: 13141 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:19.247757805Z 48 PC: 13770 | Get DOS version
2018-12-17T23:00:19.250254125Z 67 PC: 13006 | Get or set file attributes
2018-12-17T23:00:19.26034504Z 61 PC: 13622 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:19.26624067Z 64 PC: 136f5 | Write file or device (Write 4704 bytes on handle 6)
2018-12-17T23:00:19.272260614Z 66 PC: 13754 | Move file pointer
2018-12-17T23:00:19.273426532Z 64 PC: 136f5 | Write file or device (Write 4704 bytes on handle 6)
2018-12-17T23:00:19.278661957Z 66 PC: 13754 | Move file pointer
2018-12-17T23:00:19.280495464Z 64 PC: 136f5 | Write file or device (Write 5 bytes on handle 6)
2018-12-17T23:00:19.282521093Z 62 PC: 13672 | Close file
2018-12-17T23:00:19.288567515Z 64 PC: 1357d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:00:19.29144739Z 37 PC: 13311 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:19.292633602Z 37 PC: 13311 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:19.293824362Z 37 PC: 13311 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:19.296809356Z 37 PC: 13311 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:19.298539663Z 37 PC: 13311 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:19.299947642Z 37 PC: 13311 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:19.302637717Z 37 PC: 13311 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:19.306261691Z 37 PC: 13311 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:19.317598685Z 37 PC: 13311 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:19.319941747Z 37 PC: 13311 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:19.321130202Z 37 PC: 13311 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:19.322491336Z 37 PC: 13311 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:19.324567397Z 37 PC: 13311 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:19.325718693Z 37 PC: 13311 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:19.326808757Z 37 PC: 13311 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:19.328998043Z 37 PC: 13311 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:19.330136607Z 37 PC: 13311 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:19.331241895Z 37 PC: 13311 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:19.333489302Z 37 PC: 13311 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:19.335473078Z 76 PC: 13350 | Terminate with return code (Return code = '0')