Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3966.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:20.242307438Z 53 PC: 13062 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:20.243943916Z 53 PC: 13062 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:20.245354018Z 53 PC: 13062 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:20.246737257Z 53 PC: 13062 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:20.249492315Z 53 PC: 13062 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:20.251108658Z 53 PC: 13062 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:20.252187097Z 53 PC: 13062 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:20.253916969Z 53 PC: 13062 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:20.255069292Z 53 PC: 13062 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:20.256156622Z 53 PC: 13062 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:20.265101627Z 53 PC: 13062 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:20.266456183Z 53 PC: 13062 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:20.267830084Z 53 PC: 13062 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:20.269582381Z 53 PC: 13062 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:20.271161656Z 53 PC: 13062 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:20.272626813Z 53 PC: 13062 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:20.274146838Z 53 PC: 13062 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:20.27619605Z 53 PC: 13062 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:20.277324527Z 53 PC: 13062 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:20.278419097Z 37 PC: 13077 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:20.279869249Z 37 PC: 1307f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:20.28098475Z 37 PC: 13087 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:20.282078169Z 37 PC: 1308f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:20.284131558Z 68 PC: 13662 | I/O control for devices (Set for = '')
2018-12-17T23:03:20.285717166Z 48 PC: 13c91 | Get DOS version
2018-12-17T23:03:20.287376994Z 61 PC: 13ab7 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:20.294800983Z 63 PC: 13b8a | Read file or device (Read 3960 bytes on handle 5)
2018-12-17T23:03:20.30205299Z 62 PC: 13b07 | Close file
2018-12-17T23:03:20.303853037Z 26 PC: 12ee5 | Set disk transfer address
2018-12-17T23:03:20.305471093Z 78 PC: 12ef1 | Find first file
2018-12-17T23:03:20.311840477Z 61 PC: 13ab7 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:03:20.318810425Z 66 PC: 13c53 | Move file pointer
2018-12-17T23:03:20.320566418Z 66 PC: 13c61 | Move file pointer
2018-12-17T23:03:20.321885888Z 66 PC: 13c6f | Move file pointer
2018-12-17T23:03:20.323449429Z 63 PC: 13b8a | Read file or device (Read 6232 bytes on handle 5)
2018-12-17T23:03:20.332368371Z 63 PC: 13b8a | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:20.335149061Z 26 PC: 12f09 | Set disk transfer address
2018-12-17T23:03:20.336238759Z 79 PC: 12f0e | Find next file
2018-12-17T23:03:20.339355321Z 61 PC: 13ab7 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:20.345739747Z 66 PC: 13c53 | Move file pointer
2018-12-17T23:03:20.346938383Z 66 PC: 13c61 | Move file pointer
2018-12-17T23:03:20.34894904Z 66 PC: 13c6f | Move file pointer
2018-12-17T23:03:20.350738637Z 66 PC: 13be9 | Move file pointer
2018-12-17T23:03:20.352414034Z 63 PC: 13b8a | Read file or device (Read 6 bytes on handle 6)
2018-12-17T23:03:20.356346988Z 66 PC: 13be9 | Move file pointer
2018-12-17T23:03:20.357926314Z 63 PC: 13b8a | Read file or device (Read 1000 bytes on handle 6)
2018-12-17T23:03:20.365235747Z 62 PC: 13b07 | Close file
2018-12-17T23:03:20.367356056Z 60 PC: 13ab7 | Create or truncate file
2018-12-17T23:03:20.385426511Z 64 PC: 13b8a | Write file or device (Write 1000 bytes on handle 6)
2018-12-17T23:03:20.393726814Z 62 PC: 13b07 | Close file
2018-12-17T23:03:20.402282281Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:20.403312145Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:20.404273343Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:20.405675523Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:20.407130362Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:20.40800046Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:20.408914564Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:20.40995703Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:20.410759582Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:20.411607542Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:20.412952433Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:20.413903214Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:20.414700507Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:20.416504476Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:20.417968619Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:20.41944631Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:20.421779796Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:20.42350955Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:20.424935978Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:20.427634964Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:20.429165506Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:20.430503673Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:20.432133229Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:20.433151294Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:20.434125441Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:20.435876565Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:20.436825872Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:20.437821702Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:20.439269281Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:20.440284325Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:20.441227459Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:20.442850818Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:20.443860577Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:20.444991772Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:20.446465031Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:20.447490845Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:20.448530236Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:20.449986397Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:20.451059692Z 41 PC: 12fd5 | Parse filename
2018-12-17T23:03:20.45223975Z 41 PC: 12fe3 | Parse filename
2018-12-17T23:03:20.45399399Z 75 PC: 12fee | Execute program