Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Taras.5046

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:42.091300805Z 53 PC: 137aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:42.093158345Z 53 PC: 137aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:42.094307967Z 53 PC: 137aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:42.095396513Z 53 PC: 137aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:42.097252456Z 53 PC: 137aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:42.098609554Z 53 PC: 137aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:42.099949801Z 53 PC: 137aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:42.104711471Z 53 PC: 137aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:42.111630222Z 53 PC: 137aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:42.112809693Z 53 PC: 137aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:42.114475274Z 53 PC: 137aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:42.115684348Z 53 PC: 137aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:42.116839564Z 53 PC: 137aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:42.124570565Z 53 PC: 137aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:42.126080624Z 53 PC: 137aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:42.127358335Z 53 PC: 137aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:42.129158625Z 53 PC: 137aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:42.13041722Z 53 PC: 137aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:42.131645892Z 53 PC: 137aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:42.133694498Z 37 PC: 137bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:42.134770432Z 37 PC: 137c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:42.135838911Z 37 PC: 137cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:42.137204671Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:42.139336212Z 68 PC: 141ea | I/O control for devices (Set for = '')
2018-12-17T23:03:42.140978255Z 48 PC: 13e2f | Get DOS version
2018-12-17T23:03:42.142374542Z 53 PC: 134bf | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:03:42.144319361Z 37 PC: 134db | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:03:42.14578218Z 53 PC: 134bf | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:03:42.147299783Z 37 PC: 134db | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:03:42.149148241Z 53 PC: 134bf | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:42.150668474Z 37 PC: 134db | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:42.152105725Z 51 PC: 133ad | Get or set Ctrl-Break
2018-12-17T23:03:42.153759137Z 60 PC: 13c6d | Create or truncate file
2018-12-17T23:03:42.171237869Z 65 PC: 13db6 | Delete file (Filename = '\�')
2018-12-17T23:03:42.182744979Z 48 PC: 13e2f | Get DOS version
2018-12-17T23:03:42.184846817Z 61 PC: 13c6d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:42.191560246Z 66 PC: 13d9f | Move file pointer
2018-12-17T23:03:42.1930569Z 63 PC: 13d40 | Read file or device (Read 52 bytes on handle 6)
2018-12-17T23:03:42.200610815Z 62 PC: 13cbd | Close file
2018-12-17T23:03:42.20305158Z 64 PC: 13bc8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:03:42.205037037Z 37 PC: 13901 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:42.217848268Z 37 PC: 13901 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:42.218927506Z 37 PC: 13901 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:42.220005465Z 37 PC: 13901 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:42.221468931Z 37 PC: 13901 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:42.222539231Z 37 PC: 13901 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:42.223606068Z 37 PC: 13901 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:42.225700838Z 37 PC: 13901 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:42.227023623Z 37 PC: 13901 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:42.22830703Z 37 PC: 13901 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:42.231094449Z 37 PC: 13901 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:42.232395641Z 37 PC: 13901 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:42.233533833Z 37 PC: 13901 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:42.235580671Z 37 PC: 13901 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:42.237051468Z 37 PC: 13901 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:42.238540916Z 37 PC: 13901 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:42.240935106Z 37 PC: 13901 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:42.242359845Z 37 PC: 13901 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:42.243757784Z 37 PC: 13901 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:42.245650468Z 76 PC: 13940 | Terminate with return code (Return code = '8')