Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Lumin.5000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:57.009310609Z 53 PC: 1301a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:57.011754245Z 53 PC: 1301a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:57.014506952Z 53 PC: 1301a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:57.016398128Z 53 PC: 1301a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.018035858Z 53 PC: 1301a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:57.021098578Z 53 PC: 1301a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:57.023599882Z 53 PC: 1301a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:57.026058776Z 53 PC: 1301a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:57.031402816Z 53 PC: 1301a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:57.032813699Z 53 PC: 1301a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:57.034258096Z 53 PC: 1301a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:57.03609491Z 53 PC: 1301a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:57.038170764Z 53 PC: 1301a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:57.039681635Z 53 PC: 1301a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:57.042131282Z 53 PC: 1301a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:57.044784371Z 53 PC: 1301a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:57.046167923Z 53 PC: 1301a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:57.047879572Z 53 PC: 1301a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:57.050761843Z 53 PC: 1301a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:57.054042723Z 37 PC: 1302f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:57.055153872Z 37 PC: 13037 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:57.05696606Z 37 PC: 1303f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:57.058189872Z 37 PC: 13047 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:57.059615823Z 68 PC: 13eef | I/O control for devices (Set for = '>LQ_in~�������� &+:DX]bu��������� �������')
2018-12-17T23:04:57.062434094Z 48 PC: 13b05 | Get DOS version
2018-12-17T23:04:57.063880063Z 67 PC: 12dff | Get or set file attributes
2018-12-17T23:04:57.069245373Z 67 PC: 12e26 | Get or set file attributes
2018-12-17T23:04:57.091148534Z 61 PC: 13943 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:04:57.098907085Z 63 PC: 13a16 | Read file or device (Read 5000 bytes on handle 5)
2018-12-17T23:04:57.108063966Z 254 PC: 12f4c | UNKNOWN!
2018-12-17T23:04:57.110490018Z 60 PC: 13943 | Create or truncate file
2018-12-17T23:04:57.123343851Z 63 PC: 13a16 | Read file or device (Read 8192 bytes on handle 5)
2018-12-17T23:04:57.125956484Z 66 PC: 13fee | Move file pointer
2018-12-17T23:04:57.128545163Z 66 PC: 13ffc | Move file pointer
2018-12-17T23:04:57.131809943Z 66 PC: 1400a | Move file pointer
2018-12-17T23:04:57.133819291Z 62 PC: 13993 | Close file
2018-12-17T23:04:57.136438527Z 67 PC: 12e26 | Get or set file attributes
2018-12-17T23:04:57.148107091Z 62 PC: 13993 | Close file
2018-12-17T23:04:57.150713884Z 254 PC: 12f4c | UNKNOWN!
2018-12-17T23:04:57.15201482Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:57.154730767Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:57.156298977Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:57.157911449Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:57.1613257Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:57.162933113Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:57.164956067Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.16724396Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.168925041Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:57.170411336Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:57.174315258Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:57.175923042Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:57.17744857Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:57.179273222Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:57.182570052Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:57.184117001Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:57.185519319Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:57.188091576Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:57.18921531Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:57.190350725Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:57.191986811Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:57.194308057Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:57.195636735Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:57.197812187Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:57.19898377Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:57.200338788Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:57.20386514Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:57.205410907Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:57.206872555Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:57.209441417Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:57.211061624Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:57.2127771Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:57.21437244Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:57.216985364Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:57.21862113Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:57.220286542Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:57.222699029Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:57.224163934Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:57.225731492Z 41 PC: 12ed8 | Parse filename
2018-12-17T23:04:57.228342673Z 41 PC: 12ee6 | Parse filename
2018-12-17T23:04:57.230229571Z 75 PC: 12ef1 | Execute program
2018-12-17T23:04:57.23981066Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:57.242249416Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:57.244387667Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:57.245912053Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:57.247487767Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:57.250040938Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:57.251635337Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.25323738Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.255818714Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:57.257428161Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:57.259054319Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:57.261474901Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:57.263423786Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:57.265091623Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:57.268927818Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:57.270686886Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:57.272260926Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:57.273659255Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:57.275553978Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:57.276917312Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:57.278249157Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:57.280499459Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:57.281842275Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:57.283188897Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:57.28529109Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:57.286687155Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:57.287983273Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:57.2904382Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:57.292768673Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:57.294416942Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:57.296231204Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:57.298965797Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:57.30058947Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:57.302236999Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:57.304525402Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:57.30581628Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:57.307098462Z 53 PC: 12f89 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:57.30927759Z 37 PC: 12f92 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:57.310827514Z 65 PC: 13a8c | Delete file (Filename = 'Runme.Exe')
2018-12-17T23:04:57.322813475Z 254 PC: 12f4c | UNKNOWN!
2018-12-17T23:04:57.324667572Z 53 PC: 12e3c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.326126034Z 37 PC: 12e58 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:57.327576432Z 49 PC: 12e73 | Terminate and stay resident (Return code = '0' | Memory size = '1733')