Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3966.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:41.297849041Z 53 PC: 13062 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.299930208Z 53 PC: 13062 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:41.302072896Z 53 PC: 13062 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:41.304050447Z 53 PC: 13062 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:41.305982556Z 53 PC: 13062 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.308088308Z 53 PC: 13062 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.309455241Z 53 PC: 13062 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:41.310891483Z 53 PC: 13062 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:41.313154384Z 53 PC: 13062 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:41.314599368Z 53 PC: 13062 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:41.316028242Z 53 PC: 13062 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:41.31829229Z 53 PC: 13062 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:41.319880424Z 53 PC: 13062 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:41.321364402Z 53 PC: 13062 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:41.323098031Z 53 PC: 13062 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:41.324766293Z 53 PC: 13062 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:41.326143033Z 53 PC: 13062 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:41.327995449Z 53 PC: 13062 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.330689258Z 53 PC: 13062 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:41.332533571Z 37 PC: 13077 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.334214029Z 37 PC: 1307f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.336931098Z 37 PC: 13087 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.338511035Z 37 PC: 1308f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.340303861Z 68 PC: 13662 | I/O control for devices (Set for = '')
2018-12-17T23:03:41.343274947Z 48 PC: 13c91 | Get DOS version
2018-12-17T23:03:41.345452822Z 61 PC: 13ab7 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:41.353572827Z 63 PC: 13b8a | Read file or device (Read 3960 bytes on handle 5)
2018-12-17T23:03:41.363864409Z 62 PC: 13b07 | Close file
2018-12-17T23:03:41.366240469Z 26 PC: 12ee5 | Set disk transfer address
2018-12-17T23:03:41.375230842Z 78 PC: 12ef1 | Find first file
2018-12-17T23:03:41.384389428Z 61 PC: 13ab7 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:03:41.392571795Z 66 PC: 13c53 | Move file pointer
2018-12-17T23:03:41.394585772Z 66 PC: 13c61 | Move file pointer
2018-12-17T23:03:41.396567481Z 66 PC: 13c6f | Move file pointer
2018-12-17T23:03:41.400231825Z 63 PC: 13b8a | Read file or device (Read 4960 bytes on handle 5)
2018-12-17T23:03:41.410437011Z 63 PC: 13b8a | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:41.414288489Z 26 PC: 12f09 | Set disk transfer address
2018-12-17T23:03:41.417267902Z 79 PC: 12f0e | Find next file
2018-12-17T23:03:41.424694451Z 61 PC: 13ab7 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:41.432484702Z 66 PC: 13c53 | Move file pointer
2018-12-17T23:03:41.435304489Z 66 PC: 13c61 | Move file pointer
2018-12-17T23:03:41.436986563Z 66 PC: 13c6f | Move file pointer
2018-12-17T23:03:41.439085137Z 66 PC: 13be9 | Move file pointer
2018-12-17T23:03:41.442247191Z 63 PC: 13b8a | Read file or device (Read 6 bytes on handle 6)
2018-12-17T23:03:41.448416116Z 66 PC: 13be9 | Move file pointer
2018-12-17T23:03:41.450727225Z 63 PC: 13b8a | Read file or device (Read 1000 bytes on handle 6)
2018-12-17T23:03:41.459235688Z 62 PC: 13b07 | Close file
2018-12-17T23:03:41.461911324Z 60 PC: 13ab7 | Create or truncate file
2018-12-17T23:03:41.483434295Z 64 PC: 13b8a | Write file or device (Write 1000 bytes on handle 6)
2018-12-17T23:03:41.493552303Z 62 PC: 13b07 | Close file
2018-12-17T23:03:41.504240554Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.505949755Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.507594095Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:41.510137471Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:41.511760521Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:41.513380516Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:41.515679618Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:41.517543954Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:41.519936359Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.522276693Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.523979661Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.525638178Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.527719327Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:41.536870967Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:41.53844501Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:41.550780854Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:41.552605395Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:41.554429857Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:41.558004129Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:41.559760046Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:41.561374784Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:41.562982661Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:41.565258965Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:41.566758545Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:41.568205354Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:41.570888399Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:41.572331089Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:41.573791154Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:41.579060456Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:41.580422603Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:41.581733134Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:41.584205957Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:41.585521238Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:41.587320219Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:41.589416355Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.591000168Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.592306999Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:41.593850818Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:41.595799334Z 41 PC: 12fd5 | Parse filename
2018-12-17T23:03:41.597327604Z 41 PC: 12fe3 | Parse filename
2018-12-17T23:03:41.598844696Z 75 PC: 12fee | Execute program
2018-12-17T23:03:41.615861457Z 76 PC: 28b37 | Terminate with return code (Return code = '0')
2018-12-17T23:03:41.619217871Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.62075235Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.623513958Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:41.625063685Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:41.626678733Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:41.629464154Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:41.631135383Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:41.632795186Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:41.635399568Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.637087295Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.639505747Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.641277229Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.643755799Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:41.645381709Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:41.64696615Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:41.649394804Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:41.651055992Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:41.653137854Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:41.655639887Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:41.657260039Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:41.658853356Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:41.661086915Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:41.662803677Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:41.664388575Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:41.666930787Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:41.668947504Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:41.67055906Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:41.67216413Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:41.674718929Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:41.676309239Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:41.677850611Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:41.680612691Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:41.682185459Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:41.683762964Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:41.686463756Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.688261826Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.689847518Z 53 PC: 12f4c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:41.692239233Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:41.693789366Z 61 PC: 13ab7 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:41.701324799Z 66 PC: 13c53 | Move file pointer
2018-12-17T23:03:41.704711269Z 66 PC: 13c61 | Move file pointer
2018-12-17T23:03:41.706105236Z 66 PC: 13c6f | Move file pointer
2018-12-17T23:03:41.707773959Z 63 PC: 13b8a | Read file or device (Read 994 bytes on handle 6)
2018-12-17T23:03:41.717978667Z 63 PC: 13b8a | Read file or device (Read 6 bytes on handle 6)
2018-12-17T23:03:41.721338576Z 62 PC: 13b07 | Close file
2018-12-17T23:03:41.724007426Z 60 PC: 13ab7 | Create or truncate file
2018-12-17T23:03:41.739311135Z 64 PC: 13b8a | Write file or device (Write 3960 bytes on handle 6)
2018-12-17T23:03:41.749188614Z 64 PC: 13b8a | Write file or device (Write 1000 bytes on handle 6)
2018-12-17T23:03:41.758997324Z 64 PC: 13b8a | Write file or device (Write 6 bytes on handle 6)
2018-12-17T23:03:41.763524473Z 64 PC: 13765 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:03:41.765681396Z 37 PC: 13176 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:41.767339832Z 37 PC: 13176 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:41.769541781Z 37 PC: 13176 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:41.771080018Z 37 PC: 13176 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:41.772728403Z 37 PC: 13176 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:41.775166491Z 37 PC: 13176 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:41.776439624Z 37 PC: 13176 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:41.777554574Z 37 PC: 13176 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:41.779407474Z 37 PC: 13176 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:41.781206787Z 37 PC: 13176 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:41.782592232Z 37 PC: 13176 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:41.784210169Z 37 PC: 13176 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:41.78607025Z 37 PC: 13176 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:41.787415034Z 37 PC: 13176 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:41.788738561Z 37 PC: 13176 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:41.790771211Z 37 PC: 13176 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:41.792515706Z 37 PC: 13176 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:41.793823448Z 37 PC: 13176 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:41.796191795Z 37 PC: 13176 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:41.797515771Z 76 PC: 131b5 | Terminate with return code (Return code = '0')