Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Bug.5839

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:54.23564475Z 53 PC: 137da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.237688134Z 53 PC: 137da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.249577571Z 53 PC: 137da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.250700272Z 53 PC: 137da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.252314384Z 53 PC: 137da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.253604319Z 53 PC: 137da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.254758544Z 53 PC: 137da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.256689633Z 53 PC: 137da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.257991521Z 53 PC: 137da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.269572154Z 53 PC: 137da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.272789958Z 53 PC: 137da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.273864372Z 53 PC: 137da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.274881357Z 53 PC: 137da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.288077868Z 53 PC: 137da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.289265582Z 53 PC: 137da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.29105922Z 53 PC: 137da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.293622098Z 53 PC: 137da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.29522916Z 53 PC: 137da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.297387851Z 53 PC: 137da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.300485805Z 37 PC: 137ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.301734145Z 37 PC: 137f7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.302952927Z 37 PC: 137ff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.304223197Z 37 PC: 13807 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.306613141Z 68 PC: 1443d | I/O control for devices (Set for = '���\')
2018-12-17T23:03:54.415846459Z 37 PC: 13061 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.418105085Z 48 PC: 1404e | Get DOS version
2018-12-17T23:03:54.420857324Z 61 PC: 13f00 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:54.427819922Z 66 PC: 1453c | Move file pointer
2018-12-17T23:03:54.429583787Z 66 PC: 1454a | Move file pointer
2018-12-17T23:03:54.432433638Z 66 PC: 14558 | Move file pointer
2018-12-17T23:03:54.434192754Z 87 PC: 135ee | Get or set file date and time
2018-12-17T23:03:54.436183344Z 63 PC: 13fd3 | Read file or device (Read 5830 bytes on handle 5)
2018-12-17T23:03:54.445338796Z 26 PC: 1364b | Set disk transfer address
2018-12-17T23:03:54.44702778Z 78 PC: 13657 | Find first file
2018-12-17T23:03:54.455903634Z 61 PC: 13f00 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:03:54.463581982Z 66 PC: 1453c | Move file pointer
2018-12-17T23:03:54.46539979Z 66 PC: 1454a | Move file pointer
2018-12-17T23:03:54.467241027Z 66 PC: 14558 | Move file pointer
2018-12-17T23:03:54.469605369Z 63 PC: 13fd3 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T23:03:54.473076343Z 66 PC: 14032 | Move file pointer
2018-12-17T23:03:54.474836421Z 63 PC: 13fd3 | Read file or device (Read 9 bytes on handle 6)
2018-12-17T23:03:54.48378677Z 62 PC: 13f50 | Close file
2018-12-17T23:03:54.486376693Z 26 PC: 1366f | Set disk transfer address
2018-12-17T23:03:54.487735601Z 79 PC: 13674 | Find next file
2018-12-17T23:03:54.491215959Z 66 PC: 14032 | Move file pointer
2018-12-17T23:03:54.493165104Z 63 PC: 13fd3 | Read file or device (Read 5830 bytes on handle 5)
2018-12-17T23:03:54.501174372Z 66 PC: 14032 | Move file pointer
2018-12-17T23:03:54.503934475Z 64 PC: 13fd3 | Write file or device (Write 5830 bytes on handle 5)
2018-12-17T23:03:54.521018265Z 66 PC: 14032 | Move file pointer
2018-12-17T23:03:54.522846962Z 64 PC: 13f31 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T23:03:54.531939306Z 62 PC: 13f50 | Close file
2018-12-17T23:03:54.540251715Z 53 PC: 1374c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.541453545Z 37 PC: 13755 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.543407577Z 53 PC: 1374c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.544812956Z 37 PC: 13755 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.546351902Z 53 PC: 1374c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.548678587Z 37 PC: 13755 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.550493194Z 53 PC: 1374c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.552084467Z 37 PC: 13755 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.554246441Z 53 PC: 1374c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.556020502Z 37 PC: 13755 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.557401979Z 53 PC: 1374c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.558998327Z 37 PC: 13755 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.562447488Z 53 PC: 1374c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.563839497Z 37 PC: 13755 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.565205253Z 53 PC: 1374c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.566787117Z 37 PC: 13755 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.567984367Z 53 PC: 1374c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.569097087Z 37 PC: 13755 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.575815045Z 53 PC: 1374c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.57791354Z 37 PC: 13755 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.579385699Z 53 PC: 1374c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.581573429Z 37 PC: 13755 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.583094975Z 53 PC: 1374c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.584609603Z 37 PC: 13755 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.58694262Z 53 PC: 1374c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.588380208Z 37 PC: 13755 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.589747569Z 53 PC: 1374c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.591971844Z 37 PC: 13755 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.59331338Z 53 PC: 1374c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.59473479Z 37 PC: 13755 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.596741696Z 53 PC: 1374c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.59815136Z 37 PC: 13755 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.599530019Z 53 PC: 1374c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.601665826Z 37 PC: 13755 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.603076351Z 53 PC: 1374c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.604539487Z 37 PC: 13755 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.606838754Z 53 PC: 1374c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.608277658Z 37 PC: 13755 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.609739152Z 48 PC: 1404e | Get DOS version
2018-12-17T23:03:54.61254203Z 41 PC: 13703 | Parse filename
2018-12-17T23:03:54.614230049Z 41 PC: 13711 | Parse filename
2018-12-17T23:03:54.6158964Z 75 PC: 1371c | Execute program
2018-12-17T23:03:54.632848234Z 9 PC: 20b7c | Display string (Could not find end pointer)
2018-12-17T23:03:54.638493843Z 76 PC: 20b81 | Terminate with return code (Return code = '0')
2018-12-17T23:03:54.641738457Z 53 PC: 1374c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.644775583Z 37 PC: 13755 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.646679079Z 53 PC: 1374c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.648143417Z 37 PC: 13755 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.650380584Z 53 PC: 1374c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.652212926Z 37 PC: 13755 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.653641848Z 53 PC: 1374c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.655824737Z 37 PC: 13755 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.657553846Z 53 PC: 1374c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.659019253Z 37 PC: 13755 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.661185737Z 53 PC: 1374c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.662977563Z 37 PC: 13755 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.6644351Z 53 PC: 1374c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.666004288Z 37 PC: 13755 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.667746872Z 53 PC: 1374c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.669228745Z 37 PC: 13755 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.670942396Z 53 PC: 1374c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.672812057Z 37 PC: 13755 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.674249136Z 53 PC: 1374c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.675937613Z 37 PC: 13755 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.677568452Z 53 PC: 1374c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.678757348Z 37 PC: 13755 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.680770884Z 53 PC: 1374c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.682261255Z 37 PC: 13755 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.683740355Z 53 PC: 1374c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.685272377Z 37 PC: 13755 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.7024533Z 53 PC: 1374c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.704408993Z 37 PC: 13755 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.706174868Z 53 PC: 1374c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.708611953Z 37 PC: 13755 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.710422321Z 53 PC: 1374c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.712211446Z 37 PC: 13755 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.714533777Z 53 PC: 1374c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.718319344Z 37 PC: 13755 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.720557883Z 53 PC: 1374c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.724547759Z 37 PC: 13755 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.726297389Z 53 PC: 1374c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.728430729Z 37 PC: 13755 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.729833757Z 48 PC: 1404e | Get DOS version
2018-12-17T23:03:54.732736581Z 61 PC: 13f00 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:54.741044595Z 63 PC: 13fd3 | Read file or device (Read 5830 bytes on handle 5)
2018-12-17T23:03:54.750286162Z 66 PC: 1453c | Move file pointer
2018-12-17T23:03:54.751988148Z 66 PC: 1454a | Move file pointer
2018-12-17T23:03:54.754471652Z 66 PC: 14558 | Move file pointer
2018-12-17T23:03:54.756501457Z 66 PC: 14032 | Move file pointer
2018-12-17T23:03:54.758296065Z 64 PC: 13fd3 | Write file or device (Write 5830 bytes on handle 5)
2018-12-17T23:03:54.769596266Z 64 PC: 13fd3 | Write file or device (Write 9 bytes on handle 5)
2018-12-17T23:03:54.773379824Z 66 PC: 14032 | Move file pointer
2018-12-17T23:03:54.775171309Z 64 PC: 13fd3 | Write file or device (Write 5830 bytes on handle 5)
2018-12-17T23:03:54.784390063Z 87 PC: 1361b | Get or set file date and time
2018-12-17T23:03:54.791384521Z 62 PC: 13f50 | Close file
2018-12-17T23:03:54.800143042Z 37 PC: 13931 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.802323241Z 37 PC: 13931 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.803486204Z 37 PC: 13931 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.804582114Z 37 PC: 13931 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.806850935Z 37 PC: 13931 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.809120694Z 37 PC: 13931 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.810609328Z 37 PC: 13931 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.813101475Z 37 PC: 13931 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.814452677Z 37 PC: 13931 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.815523551Z 37 PC: 13931 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.817416298Z 37 PC: 13931 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.818546605Z 37 PC: 13931 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.819601708Z 37 PC: 13931 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.821421756Z 37 PC: 13931 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.822380831Z 37 PC: 13931 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.82330425Z 37 PC: 13931 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.824884796Z 37 PC: 13931 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.826046388Z 37 PC: 13931 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.827069158Z 37 PC: 13931 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.829000848Z 76 PC: 13970 | Terminate with return code (Return code = '0')