Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Usa.6639

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:44.997636507Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.011014229Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:45.012109886Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:45.013145565Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.01457401Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.015567842Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.016557389Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:45.017882907Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:45.018907839Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:45.019907106Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:45.021295557Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:45.02225843Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:45.023237823Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:45.024544522Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:45.026593513Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:45.027596868Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:45.030087403Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:45.031229053Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.032278377Z 53 PC: 13bfa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:45.033440302Z 37 PC: 13c0f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.034488341Z 37 PC: 13c17 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.035339878Z 37 PC: 13c1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.036386537Z 37 PC: 13c27 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.037756972Z 68 PC: 147fd | I/O control for devices (Set for = '�6y��^�l���t��9�B�t�T���')
2018-12-17T23:01:45.096296323Z 37 PC: 13271 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:45.09783551Z 42 PC: 137f7 | Get date 0x137f7: xor ah, ah
0x137f9: les di, ptr [bp + 6]
0x137fc: stosw word ptr es:[di], ax
0x137fd: mov al, dl
0x137ff: les di, ptr [bp + 0xa]
0x13802: stosw word ptr es:[di], ax
0x13803: mov al, dh
0x13805: les di, ptr [bp + 0xe]
0x13808: stosw word ptr es:[di], ax
0x13809: xchg ax, cx
0x1380a: les di, ptr [bp + 0x12]
0x1380d: stosw word ptr es:[di], ax
0x1380e: pop bp
0x1380f: retf 0x10
0x13812: push bp
0x13813: mov bp, sp
0x13815: mov cx, word ptr [bp + 0xa]
0x13818: mov dh, byte ptr [bp + 8]
0x1381b: mov dl, byte ptr [bp + 6]
0x1381e: mov ah, 0x2b
2018-12-17T23:01:45.100520873Z 60 PC: 147e1 | Create or truncate file
2018-12-17T23:01:45.117687277Z 68 PC: 147fd | I/O control for devices (Set for = '�6y��^�l���t��9�B�t�T���')
2018-12-17T23:01:45.119669927Z 64 PC: 13ff3 | Write file or device (Write 31 bytes on handle 5)
2018-12-17T23:01:45.123354954Z 62 PC: 14032 | Close file
2018-12-17T23:01:45.131200474Z 48 PC: 1440e | Get DOS version
2018-12-17T23:01:45.132853403Z 26 PC: 13887 | Set disk transfer address
2018-12-17T23:01:45.134501674Z 78 PC: 13893 | Find first file
2018-12-17T23:01:45.14079377Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.141913832Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.143299833Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:45.144641503Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:45.145737245Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:45.147081373Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:45.148032024Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.149020034Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.150071468Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.151043949Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.152003107Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.153069591Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.154078774Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:45.15508714Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:45.156422283Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:45.157392967Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:45.158319521Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:45.159439446Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:45.160400057Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:45.161375607Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:45.162363725Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:45.163336424Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:45.164998233Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:45.16608061Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:45.167017208Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:45.168047236Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:45.169345431Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:45.170359104Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:45.171324377Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:45.172412354Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:45.173354679Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:45.17421595Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:45.175303786Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:45.176270203Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:45.177231561Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.17851794Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.179458545Z 53 PC: 13b6d | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:45.18032513Z 37 PC: 13b76 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:45.181896865Z 41 PC: 13b24 | Parse filename
2018-12-17T23:01:45.183128364Z 41 PC: 13b32 | Parse filename
2018-12-17T23:01:45.184525674Z 75 PC: 13b3d | Execute program
2018-12-17T23:01:45.205302605Z 80 PC: 177d9 | Set current PSP
2018-12-17T23:01:45.20603785Z 48 PC: 177de | Get DOS version
2018-12-17T23:01:45.207382596Z 99 PC: 1dfc0 | Get DBCS lead byte table pointer
2018-12-17T23:01:45.209844025Z 101 PC: 17864 | Get extended country info
2018-12-17T23:01:45.210941925Z 99 PC: 1786a | Get DBCS lead byte table pointer
2018-12-17T23:01:45.212018897Z 74 PC: 178cc | Reallocate memory
2018-12-17T23:01:45.213529627Z 25 PC: 17903 | Get default drive
2018-12-17T23:01:45.21445135Z 37 PC: 173c3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:01:45.215419317Z 37 PC: 173ca | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.216492342Z 37 PC: 173d1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.220511552Z 74 PC: 1656c | Reallocate memory
2018-12-17T23:01:45.221795183Z 72 PC: 165ad | Allocate memory
2018-12-17T23:01:45.2234853Z 72 PC: 165e5 | Allocate memory
2018-12-17T23:01:45.22552132Z 72 PC: 165ed | Allocate memory