Sample viewer

vx.netlux.org/Virus.DOS.HLLP.SM.4758

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:21.765635221Z 53 PC: 1344a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:21.766796103Z 53 PC: 1344a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:21.768315914Z 53 PC: 1344a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:21.769463335Z 53 PC: 1344a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:21.770594709Z 53 PC: 1344a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:21.772206289Z 53 PC: 1344a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:21.773341472Z 53 PC: 1344a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:21.774474406Z 53 PC: 1344a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:21.77598809Z 53 PC: 1344a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:21.777141035Z 53 PC: 1344a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:21.778273325Z 53 PC: 1344a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:21.779885307Z 53 PC: 1344a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:21.781099715Z 53 PC: 1344a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:21.782230498Z 53 PC: 1344a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:21.7845506Z 53 PC: 1344a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:21.785750623Z 53 PC: 1344a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:21.786784712Z 53 PC: 1344a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:21.787890976Z 53 PC: 1344a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:21.799623455Z 53 PC: 1344a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:21.800836628Z 37 PC: 1345f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:21.80196925Z 37 PC: 13467 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:21.80366179Z 37 PC: 1346f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:21.804724759Z 37 PC: 13477 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:21.806142253Z 68 PC: 13fed | I/O control for devices (Set for = '������^�QW�G����')
2018-12-17T23:00:21.807862259Z 53 PC: 133bd | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:21.809048174Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:21.810148727Z 53 PC: 133bd | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:21.811809357Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:21.813015021Z 53 PC: 133bd | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:21.814198256Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:21.816062191Z 53 PC: 133bd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:21.817419969Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:21.818615592Z 53 PC: 133bd | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:21.820391811Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:21.821810526Z 53 PC: 133bd | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:21.823074696Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:21.824487874Z 53 PC: 133bd | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:21.825921967Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:21.827307043Z 53 PC: 133bd | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:21.828540704Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:21.830031324Z 53 PC: 133bd | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:21.831333275Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:21.832403919Z 53 PC: 133bd | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:21.834237498Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:21.835448978Z 53 PC: 133bd | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:21.836681758Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:21.838260278Z 53 PC: 133bd | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:21.839458482Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:21.840612669Z 53 PC: 133bd | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:21.8424327Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:21.843633516Z 53 PC: 133bd | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:21.844817854Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:21.846387432Z 53 PC: 133bd | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:21.847673022Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:21.848790477Z 53 PC: 133bd | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:21.850415939Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:21.85156102Z 53 PC: 133bd | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:21.852600568Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:21.854058316Z 53 PC: 133bd | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:21.855248416Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:21.856210061Z 53 PC: 133bd | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:21.857699239Z 37 PC: 133c6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:21.858986812Z 48 PC: 13c03 | Get DOS version
2018-12-17T23:00:21.860524376Z 48 PC: 13c03 | Get DOS version
2018-12-17T23:00:21.86212122Z 48 PC: 13c03 | Get DOS version
2018-12-17T23:00:21.86380241Z 48 PC: 13c03 | Get DOS version
2018-12-17T23:00:21.865276515Z 72 PC: 12a47 | Allocate memory
2018-12-17T23:00:21.867048361Z 72 PC: 12a65 | Allocate memory
2018-12-17T23:00:21.868627993Z 48 PC: 13c03 | Get DOS version
2018-12-17T23:00:21.869896438Z 67 PC: 1326f | Get or set file attributes
2018-12-17T23:00:21.876610363Z 67 PC: 13296 | Get or set file attributes
2018-12-17T23:00:21.895283546Z 61 PC: 13ab5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:00:21.900456487Z 87 PC: 132b0 | Get or set file date and time
2018-12-17T23:00:21.901719798Z 66 PC: 140ec | Move file pointer
2018-12-17T23:00:21.904182475Z 66 PC: 140fa | Move file pointer
2018-12-17T23:00:21.905682587Z 66 PC: 14108 | Move file pointer
2018-12-17T23:00:21.907269957Z 66 PC: 13be7 | Move file pointer
2018-12-17T23:00:21.909320126Z 63 PC: 13b88 | Read file or device (Read 4758 bytes on handle 5)
2018-12-17T23:00:21.918325113Z 66 PC: 13be7 | Move file pointer
2018-12-17T23:00:21.919908036Z 64 PC: 13b88 | Write file or device (Write 4758 bytes on handle 5)
2018-12-17T23:00:21.93049551Z 66 PC: 140ec | Move file pointer
2018-12-17T23:00:21.932149985Z 66 PC: 140fa | Move file pointer
2018-12-17T23:00:21.933753802Z 66 PC: 14108 | Move file pointer
2018-12-17T23:00:21.936394085Z 66 PC: 13be7 | Move file pointer
2018-12-17T23:00:21.937968116Z 64 PC: 13ae6 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T23:00:21.947596219Z 87 PC: 132dd | Get or set file date and time
2018-12-17T23:00:21.949102654Z 62 PC: 13b05 | Close file
2018-12-17T23:00:21.957888769Z 67 PC: 13296 | Get or set file attributes
2018-12-17T23:00:21.969142119Z 74 PC: 12a57 | Reallocate memory
2018-12-17T23:00:21.971279817Z 48 PC: 13c03 | Get DOS version
2018-12-17T23:00:21.973669751Z 41 PC: 13374 | Parse filename
2018-12-17T23:00:21.975240542Z 41 PC: 13382 | Parse filename
2018-12-17T23:00:21.976807308Z 75 PC: 1338d | Execute program