Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Lugad.4805

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:54.507463216Z 53 PC: 1321a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.509366436Z 53 PC: 1321a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.510704759Z 53 PC: 1321a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.51210825Z 53 PC: 1321a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.514306424Z 53 PC: 1321a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.5152753Z 53 PC: 1321a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.516400549Z 53 PC: 1321a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.518494587Z 53 PC: 1321a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.519782894Z 53 PC: 1321a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.520899855Z 53 PC: 1321a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.5333669Z 53 PC: 1321a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.534954582Z 53 PC: 1321a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.535906067Z 53 PC: 1321a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.537665093Z 53 PC: 1321a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.539524043Z 53 PC: 1321a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.541080186Z 53 PC: 1321a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.542615545Z 53 PC: 1321a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.543767678Z 53 PC: 1321a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.545261211Z 53 PC: 1321a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.547030672Z 37 PC: 1322f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.548083282Z 37 PC: 13237 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.549099825Z 37 PC: 1323f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.550772423Z 37 PC: 13247 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.55394762Z 68 PC: 13aa5 | I/O control for devices (Set for = '')
2018-12-17T23:03:54.556658463Z 42 PC: 12f77 | Get date 0x12f77: mov byte ptr [0x56], dh
0x12f7b: mov byte ptr [0x57], dl
0x12f7f: mov ah, 0x2c
0x12f81: int 0x21
0x12f83: mov byte ptr [0x58], dh
0x12f87: cmp byte ptr [0x58], 0xf
0x12f8c: jae 0x12f93
0x12f8e: mov byte ptr [0x29b3], 1
0x12f93: cmp byte ptr [0x57], 0x1f
0x12f98: mov al, 0
0x12f9a: jne 0x12f9d
0x12f9c: inc ax
0x12f9d: mov dl, al
0x12f9f: cmp byte ptr [0x56], 1
0x12fa4: mov al, 0
0x12fa6: jne 0x12fa9
0x12fa8: inc ax
0x12fa9: and al, dl
0x12fab: or al, al
0x12fad: je 0x12fd1
2018-12-17T23:03:54.560398162Z 44 PC: 12f83 | Get time 0x12f83: mov byte ptr [0x58], dh
0x12f87: cmp byte ptr [0x58], 0xf
0x12f8c: jae 0x12f93
0x12f8e: mov byte ptr [0x29b3], 1
0x12f93: cmp byte ptr [0x57], 0x1f
0x12f98: mov al, 0
0x12f9a: jne 0x12f9d
0x12f9c: inc ax
0x12f9d: mov dl, al
0x12f9f: cmp byte ptr [0x56], 1
0x12fa4: mov al, 0
0x12fa6: jne 0x12fa9
0x12fa8: inc ax
0x12fa9: and al, dl
0x12fab: or al, al
0x12fad: je 0x12fd1
0x12faf: mov di, 0x501
0x12fb2: push cs
0x12fb3: push di
0x12fb4: mov di, 0x5a
2018-12-17T23:03:54.563109254Z 48 PC: 137d0 | Get DOS version
2018-12-17T23:03:54.564759379Z 48 PC: 137d0 | Get DOS version
2018-12-17T23:03:54.567062458Z 61 PC: 13682 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:54.573973952Z 63 PC: 13755 | Read file or device (Read 4800 bytes on handle 5)
2018-12-17T23:03:54.581655226Z 62 PC: 136d2 | Close file
2018-12-17T23:03:54.584538894Z 26 PC: 13077 | Set disk transfer address
2018-12-17T23:03:54.586009424Z 78 PC: 13083 | Find first file
2018-12-17T23:03:54.5926667Z 61 PC: 13682 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:03:54.600231057Z 66 PC: 137b4 | Move file pointer
2018-12-17T23:03:54.602175091Z 63 PC: 13755 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T23:03:54.609347685Z 26 PC: 1309b | Set disk transfer address
2018-12-17T23:03:54.610672134Z 79 PC: 130a0 | Find next file
2018-12-17T23:03:54.614730077Z 48 PC: 137d0 | Get DOS version
2018-12-17T23:03:54.61642021Z 26 PC: 13077 | Set disk transfer address
2018-12-17T23:03:54.617817241Z 78 PC: 13083 | Find first file
2018-12-17T23:03:54.62455752Z 48 PC: 137d0 | Get DOS version
2018-12-17T23:03:54.626338053Z 67 PC: 13046 | Get or set file attributes
2018-12-17T23:03:54.642150513Z 61 PC: 13682 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:54.649721541Z 66 PC: 137b4 | Move file pointer
2018-12-17T23:03:54.651463177Z 63 PC: 13755 | Read file or device (Read 4800 bytes on handle 6)
2018-12-17T23:03:54.659127579Z 66 PC: 137b4 | Move file pointer
2018-12-17T23:03:54.661493271Z 64 PC: 136b3 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:03:54.669417952Z 66 PC: 137b4 | Move file pointer
2018-12-17T23:03:54.671994538Z 64 PC: 13755 | Write file or device (Write 4800 bytes on handle 6)
2018-12-17T23:03:54.680807667Z 62 PC: 136d2 | Close file
2018-12-17T23:03:54.688752169Z 53 PC: 13192 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.690269671Z 37 PC: 1319b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.692145843Z 53 PC: 13192 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.693703107Z 37 PC: 1319b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.695263244Z 53 PC: 13192 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.697784119Z 37 PC: 1319b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.699183151Z 53 PC: 13192 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.700609707Z 37 PC: 1319b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.702985625Z 53 PC: 13192 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.704182377Z 37 PC: 1319b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.705286344Z 53 PC: 13192 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.707041231Z 37 PC: 1319b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.708144638Z 53 PC: 13192 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.709243734Z 37 PC: 1319b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.711236149Z 53 PC: 13192 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.712435603Z 37 PC: 1319b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.713538113Z 53 PC: 13192 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.715604185Z 37 PC: 1319b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.716683437Z 53 PC: 13192 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.717784967Z 37 PC: 1319b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.719750681Z 53 PC: 13192 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.72085917Z 37 PC: 1319b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.722001197Z 53 PC: 13192 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.723724682Z 37 PC: 1319b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.724861971Z 53 PC: 13192 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.725974271Z 37 PC: 1319b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.727216213Z 53 PC: 13192 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.729310933Z 37 PC: 1319b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.730585635Z 53 PC: 13192 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.731896632Z 37 PC: 1319b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.734326326Z 53 PC: 13192 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.735644889Z 37 PC: 1319b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.736940028Z 53 PC: 13192 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.738915634Z 37 PC: 1319b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.740285512Z 53 PC: 13192 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.741682622Z 37 PC: 1319b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.743943641Z 53 PC: 13192 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.745313929Z 37 PC: 1319b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.746809504Z 41 PC: 13149 | Parse filename
2018-12-17T23:03:54.749555467Z 41 PC: 13157 | Parse filename
2018-12-17T23:03:54.750890227Z 75 PC: 13162 | Execute program
2018-12-17T23:03:54.766284496Z 9 PC: 17298 | Display string (Could not find end pointer)
2018-12-17T23:03:54.78059746Z 76 PC: 1729c | Terminate with return code (Return code = '36')
2018-12-17T23:03:54.783744967Z 53 PC: 13192 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.785163572Z 37 PC: 1319b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.787398703Z 53 PC: 13192 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.788760327Z 37 PC: 1319b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.790080782Z 53 PC: 13192 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.792182292Z 37 PC: 1319b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.793519606Z 53 PC: 13192 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.79491418Z 37 PC: 1319b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.797096162Z 53 PC: 13192 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.798846636Z 37 PC: 1319b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.800208101Z 53 PC: 13192 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.802275984Z 37 PC: 1319b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.803993213Z 53 PC: 13192 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.805379648Z 37 PC: 1319b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.807475316Z 53 PC: 13192 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.809212138Z 37 PC: 1319b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.810560988Z 53 PC: 13192 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.812642244Z 37 PC: 1319b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.814356994Z 53 PC: 13192 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.815736156Z 37 PC: 1319b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.817293603Z 53 PC: 13192 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.81874114Z 37 PC: 1319b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.819817671Z 53 PC: 13192 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.821172059Z 37 PC: 1319b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.82270318Z 53 PC: 13192 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.823804128Z 37 PC: 1319b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.82489291Z 53 PC: 13192 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.826504896Z 37 PC: 1319b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.82785956Z 53 PC: 13192 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.8292645Z 37 PC: 1319b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.831176507Z 53 PC: 13192 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.832547629Z 37 PC: 1319b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.833869952Z 53 PC: 13192 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.835968392Z 37 PC: 1319b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.837357427Z 53 PC: 13192 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.838756081Z 37 PC: 1319b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.840887129Z 53 PC: 13192 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.842206498Z 37 PC: 1319b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.843638691Z 48 PC: 137d0 | Get DOS version
2018-12-17T23:03:54.847231783Z 67 PC: 13046 | Get or set file attributes
2018-12-17T23:03:54.857441713Z 61 PC: 13682 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:03:54.864340324Z 64 PC: 13755 | Write file or device (Write 4800 bytes on handle 6)
2018-12-17T23:03:54.873413963Z 66 PC: 137b4 | Move file pointer
2018-12-17T23:03:54.87515553Z 64 PC: 13755 | Write file or device (Write 4800 bytes on handle 6)
2018-12-17T23:03:54.883507141Z 66 PC: 137b4 | Move file pointer
2018-12-17T23:03:54.88631645Z 64 PC: 13755 | Write file or device (Write 5 bytes on handle 6)
2018-12-17T23:03:54.889344905Z 62 PC: 136d2 | Close file
2018-12-17T23:03:54.897967869Z 64 PC: 135dd | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:03:54.901054708Z 37 PC: 13371 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:54.902934014Z 37 PC: 13371 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:54.904209518Z 37 PC: 13371 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:54.906211193Z 37 PC: 13371 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:54.907337766Z 37 PC: 13371 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:54.908419639Z 37 PC: 13371 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:54.910520558Z 37 PC: 13371 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:54.911614174Z 37 PC: 13371 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:54.912680396Z 37 PC: 13371 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:54.914733796Z 37 PC: 13371 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:54.915807524Z 37 PC: 13371 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:54.916873801Z 37 PC: 13371 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:54.918910436Z 37 PC: 13371 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:54.920038758Z 37 PC: 13371 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:54.921095567Z 37 PC: 13371 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:54.923195142Z 37 PC: 13371 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:54.925024316Z 37 PC: 13371 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:54.926172184Z 37 PC: 13371 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:54.927261869Z 37 PC: 13371 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:54.929694987Z 76 PC: 133b0 | Terminate with return code (Return code = '0')