Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Jutro.9872

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:47.655815744Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:47.657289896Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:47.658300179Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:47.659361264Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:47.662433827Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:47.663453295Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:47.664444009Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:47.666484234Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:47.667892773Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:47.669223383Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:47.670960745Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:47.672198468Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:47.673300501Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:47.674734289Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:47.675774289Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:47.676807762Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:47.678452313Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:47.679658383Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:47.694052772Z 53 PC: 13f1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:47.701414782Z 37 PC: 13f2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:47.702548862Z 37 PC: 13f37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:47.703654178Z 37 PC: 13f3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:47.708680088Z 37 PC: 13f47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:47.710357794Z 68 PC: 14c12 | I/O control for devices (Set for = '')
2018-12-17T22:02:47.711834977Z 25 PC: 147bb | Get default drive
2018-12-17T22:02:47.713479679Z 71 PC: 147ce | Get current directory
2018-12-17T22:02:47.716373928Z 48 PC: 1472e | Get DOS version
2018-12-17T22:02:47.718651101Z 26 PC: 13ce1 | Set disk transfer address
2018-12-17T22:02:47.720462518Z 78 PC: 13ced | Find first file
2018-12-17T22:02:47.727859941Z 61 PC: 145e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:02:47.734204719Z 66 PC: 14d11 | Move file pointer
2018-12-17T22:02:47.73655095Z 66 PC: 14d1f | Move file pointer
2018-12-17T22:02:47.738259459Z 66 PC: 14d2d | Move file pointer
2018-12-17T22:02:47.740325699Z 66 PC: 14d11 | Move file pointer
2018-12-17T22:02:47.742686143Z 66 PC: 14d1f | Move file pointer
2018-12-17T22:02:47.744699745Z 66 PC: 14d2d | Move file pointer
2018-12-17T22:02:47.746819074Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.753941839Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.757173943Z 66 PC: 14712 | Move file pointer
2018-12-17T22:02:47.759047426Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.766589265Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.769572373Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.772594955Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.776217035Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.778614204Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.781959421Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.785641748Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.788996105Z 66 PC: 14712 | Move file pointer
2018-12-17T22:02:47.790837422Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.795199844Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.79823192Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.802066615Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.806136001Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.809273435Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.812369423Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.81635345Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.818458936Z 63 PC: 14672 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:47.820177011Z 54 PC: 13c4c | Get free disk space
2018-12-17T22:02:47.826316912Z 62 PC: 14630 | Close file
2018-12-17T22:02:47.827920564Z 26 PC: 13d05 | Set disk transfer address
2018-12-17T22:02:47.828866849Z 79 PC: 13d0a | Find next file
2018-12-17T22:02:47.83104972Z 26 PC: 13ce1 | Set disk transfer address
2018-12-17T22:02:47.831887269Z 78 PC: 13ced | Find first file
2018-12-17T22:02:47.83572573Z 61 PC: 145e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:02:47.840306843Z 87 PC: 13c84 | Get or set file date and time
2018-12-17T22:02:47.841448207Z 66 PC: 14d11 | Move file pointer
2018-12-17T22:02:47.842494204Z 66 PC: 14d1f | Move file pointer
2018-12-17T22:02:47.844849915Z 66 PC: 14d2d | Move file pointer
2018-12-17T22:02:47.846384324Z 66 PC: 14712 | Move file pointer
2018-12-17T22:02:47.847768916Z 63 PC: 146b3 | Read file or device (Read 9872 bytes on handle 5)
2018-12-17T22:02:47.85627921Z 66 PC: 14712 | Move file pointer
2018-12-17T22:02:47.857915734Z 64 PC: 146b3 | Write file or device (Write 9872 bytes on handle 5)
2018-12-17T22:02:47.8734193Z 66 PC: 14712 | Move file pointer
2018-12-17T22:02:47.875640192Z 64 PC: 14611 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:02:47.883833387Z 87 PC: 13cb1 | Get or set file date and time
2018-12-17T22:02:47.885342566Z 62 PC: 14630 | Close file
2018-12-17T22:02:47.894452339Z 41 PC: 13e83 | Parse filename
2018-12-17T22:02:47.896090132Z 41 PC: 13e91 | Parse filename
2018-12-17T22:02:47.89754335Z 75 PC: 13e9c | Execute program
2018-12-17T22:02:47.919020643Z 80 PC: 29b59 | Set current PSP
2018-12-17T22:02:47.919778885Z 48 PC: 29b5e | Get DOS version
2018-12-17T22:02:47.921415337Z 99 PC: 30340 | Get DBCS lead byte table pointer
2018-12-17T22:02:47.924736799Z 101 PC: 29be4 | Get extended country info
2018-12-17T22:02:47.926146033Z 99 PC: 29bea | Get DBCS lead byte table pointer
2018-12-17T22:02:47.928226522Z 74 PC: 29c4c | Reallocate memory
2018-12-17T22:02:47.930374422Z 25 PC: 29c83 | Get default drive
2018-12-17T22:02:47.931335453Z 37 PC: 29743 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:02:47.93236184Z 37 PC: 2974a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:47.933785882Z 37 PC: 29751 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:47.938315967Z 74 PC: 288ec | Reallocate memory
2018-12-17T22:02:47.940178739Z 72 PC: 2892d | Allocate memory
2018-12-17T22:02:47.942609143Z 72 PC: 28965 | Allocate memory
2018-12-17T22:02:47.944598209Z 72 PC: 2896d | Allocate memory