Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Duke.5280

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:06.593845459Z 53 PC: 1316a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:06.595273853Z 53 PC: 1316a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:06.599346756Z 53 PC: 1316a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:06.601221398Z 53 PC: 1316a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:06.603149882Z 53 PC: 1316a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:06.606020998Z 53 PC: 1316a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:06.60801261Z 53 PC: 1316a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:06.609930143Z 53 PC: 1316a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:06.612426133Z 53 PC: 1316a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:06.613990092Z 53 PC: 1316a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:06.615456507Z 53 PC: 1316a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:06.617675256Z 53 PC: 1316a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:06.619396431Z 53 PC: 1316a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:06.621872554Z 53 PC: 1316a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:06.624811025Z 53 PC: 1316a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:06.626526819Z 53 PC: 1316a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:06.628054109Z 53 PC: 1316a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:06.630291854Z 53 PC: 1316a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:06.631728674Z 53 PC: 1316a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:06.633122504Z 37 PC: 1317f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:06.634418569Z 37 PC: 13187 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:06.636730313Z 37 PC: 1318f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:06.638558188Z 37 PC: 13197 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:06.640897824Z 68 PC: 13b6a | I/O control for devices (Set for = '')
2018-12-17T23:01:06.643672828Z 48 PC: 1377b | Get DOS version
2018-12-17T23:01:06.6454726Z 26 PC: 13017 | Set disk transfer address
2018-12-17T23:01:06.647147016Z 78 PC: 13023 | Find first file
2018-12-17T23:01:06.657695608Z 61 PC: 1362d | Open file (Filename = 'TEST.EXE')
2018-12-17T23:01:06.665266885Z 66 PC: 13c69 | Move file pointer
2018-12-17T23:01:06.667336314Z 66 PC: 13c77 | Move file pointer
2018-12-17T23:01:06.671284342Z 66 PC: 13c85 | Move file pointer
2018-12-17T23:01:06.673489947Z 62 PC: 1367d | Close file
2018-12-17T23:01:06.676856052Z 26 PC: 1303b | Set disk transfer address
2018-12-17T23:01:06.679481977Z 79 PC: 13040 | Find next file
2018-12-17T23:01:06.683445304Z 61 PC: 1362d | Open file (Filename = 'TEST.EXE')
2018-12-17T23:01:06.690973059Z 66 PC: 13c69 | Move file pointer
2018-12-17T23:01:06.693661912Z 66 PC: 13c77 | Move file pointer
2018-12-17T23:01:06.695903755Z 66 PC: 13c85 | Move file pointer
2018-12-17T23:01:06.698076277Z 62 PC: 1367d | Close file
2018-12-17T23:01:06.700996384Z 61 PC: 1362d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:01:06.709191383Z 66 PC: 13c69 | Move file pointer
2018-12-17T23:01:06.71165396Z 66 PC: 13c77 | Move file pointer
2018-12-17T23:01:06.713689385Z 66 PC: 13c85 | Move file pointer
2018-12-17T23:01:06.716345867Z 62 PC: 1367d | Close file
2018-12-17T23:01:06.719056741Z 64 PC: 13588 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:01:06.72144581Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:06.724192922Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:06.725953741Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:06.727758682Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:06.730175283Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:06.731946221Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:06.733714473Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:06.737064259Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:06.73888501Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:06.740639657Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:06.743493589Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:06.744830732Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:06.746083336Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:06.747291867Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:06.748960533Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:06.750287927Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:06.75155053Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:06.754224013Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:06.755670601Z 37 PC: 132c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:06.757590459Z 76 PC: 13300 | Terminate with return code (Return code = '0')