Sample viewer

vx.netlux.org/Virus.DOS.HLLP.ASEA.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:30.870409859Z 53 PC: 13cda | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:30.872782161Z 53 PC: 13cda | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:30.88645185Z 53 PC: 13cda | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:30.887987128Z 53 PC: 13cda | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:30.889827439Z 53 PC: 13cda | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:30.893323464Z 53 PC: 13cda | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:30.89510735Z 53 PC: 13cda | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:30.896978499Z 53 PC: 13cda | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:30.89992434Z 53 PC: 13cda | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:30.901416887Z 53 PC: 13cda | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:30.903751498Z 53 PC: 13cda | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:30.906060932Z 53 PC: 13cda | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:30.907797859Z 53 PC: 13cda | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:30.909269567Z 53 PC: 13cda | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:30.911736276Z 53 PC: 13cda | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:30.91352521Z 53 PC: 13cda | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:30.915269822Z 53 PC: 13cda | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:30.919142976Z 53 PC: 13cda | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:30.921050794Z 53 PC: 13cda | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:30.922860087Z 37 PC: 13cef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:30.924529568Z 37 PC: 13cf7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:30.938022245Z 37 PC: 13cff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:30.939741889Z 37 PC: 13d07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:30.941876113Z 68 PC: 14c95 | I/O control for devices (Set for = '=')
2018-12-17T23:04:30.945198963Z 53 PC: 137e1 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:04:30.946667465Z 37 PC: 137fd | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:04:30.947990012Z 44 PC: 14dcc | Get time 0x14dcc: mov word ptr [0x76], cx
0x14dd0: mov word ptr [0x78], dx
0x14dd4: retf
0x14dd5: mov cx, di
0x14dd7: mov si, 0xa
0x14dda: mov bx, dx
0x14ddc: or bx, bx
0x14dde: jns 0x14df1
0x14de0: neg bx
0x14de2: neg ax
0x14de4: sbb bx, 0
0x14de7: call 0x14df1
0x14dea: dec di
0x14deb: mov byte ptr es:[di], 0x2d
0x14def: inc cx
0x14df0: ret
0x14df1: xor dx, dx
0x14df3: xchg ax, bx
0x14df4: div si
0x14df6: xchg ax, bx
2018-12-17T23:04:30.951456442Z 48 PC: 147c5 | Get DOS version
2018-12-17T23:04:30.957516359Z 61 PC: 14603 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:04:30.970477367Z 66 PC: 14f95 | Move file pointer
2018-12-17T23:04:30.973214786Z 66 PC: 14fa3 | Move file pointer
2018-12-17T23:04:30.975387792Z 66 PC: 14fb1 | Move file pointer
2018-12-17T23:04:30.977568383Z 63 PC: 146d6 | Read file or device (Read 14908 bytes on handle 5)
2018-12-17T23:04:30.987511735Z 62 PC: 14653 | Close file
2018-12-17T23:04:30.990459119Z 48 PC: 147c5 | Get DOS version
2018-12-17T23:04:30.993257732Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.000005012Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.012840684Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.019400542Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.026856395Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.034371119Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.042213449Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.049037603Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.057972298Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.064884067Z 67 PC: 137b7 | Get or set file attributes
2018-12-17T23:04:31.073170302Z 64 PC: 1435b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:04:31.076077149Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:31.077970891Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:31.079498213Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:31.08104376Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:31.083645263Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:31.085173658Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:31.086732189Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:31.089258601Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:31.090795902Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:31.092332252Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:31.094703071Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:31.096145975Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:31.097911064Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:31.099892872Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:31.102940163Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:31.1042254Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:31.105492854Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:31.107409239Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:31.108679147Z 37 PC: 13e31 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:31.10994571Z 76 PC: 13e70 | Terminate with return code (Return code = '0')