Sample viewer

vx.netlux.org/Virus.DOS.HLLW.5552

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:58.266131013Z 53 PC: 130ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:58.270800955Z 53 PC: 130ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:58.274612743Z 53 PC: 130ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:58.276183838Z 53 PC: 130ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:58.279849963Z 53 PC: 130ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:58.282127526Z 53 PC: 130ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:58.283733616Z 53 PC: 130ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:58.285298519Z 53 PC: 130ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:58.287928886Z 53 PC: 130ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:58.289952482Z 53 PC: 130ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:58.295239995Z 53 PC: 130ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:58.303749518Z 53 PC: 130ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:58.306424259Z 53 PC: 130ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:58.308748058Z 53 PC: 130ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:58.314306031Z 53 PC: 130ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:58.316185586Z 53 PC: 130ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:58.318378079Z 53 PC: 130ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:58.32053226Z 53 PC: 130ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:58.322726125Z 53 PC: 130ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:58.324962772Z 37 PC: 130cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:58.326674792Z 37 PC: 130d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:58.328793596Z 37 PC: 130df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:58.330363509Z 37 PC: 130e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:58.333284952Z 68 PC: 139e9 | I/O control for devices (Set for = '��2ۆ3ɴN�!�r �S�@t3��O�:���II �x ����ø`��w���@')
2018-12-17T23:04:58.342412197Z 48 PC: 13714 | Get DOS version
2018-12-17T23:04:58.345513499Z 26 PC: 12e35 | Set disk transfer address
2018-12-17T23:04:58.347212915Z 78 PC: 12e41 | Find first file
2018-12-17T23:04:58.354616809Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.356325553Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.359685822Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.362240516Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.366222445Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.368088203Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.371735302Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.373891978Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.378432427Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.380165406Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.383308647Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.384880914Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.39460439Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.395842077Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.398643225Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.406904581Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.410127833Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.411606725Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.414368398Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.415414766Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.417587482Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.419416111Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.421653819Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.422736004Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.425775521Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.427166156Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.429435463Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.431231881Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.433797757Z 26 PC: 12e59 | Set disk transfer address
2018-12-17T23:04:58.434907534Z 79 PC: 12e5e | Find next file
2018-12-17T23:04:58.438332084Z 44 PC: 13e81 | Get time 0x13e81: mov word ptr [0x3e], cx
0x13e85: mov word ptr [0x40], dx
0x13e89: retf
0x13e8a: mov di, 0x50
0x13e8d: push ds
0x13e8e: pop es
0x13e8f: mov cx, 0x3b0
0x13e92: sub cx, di
0x13e94: shr cx, 1
0x13e96: xor ax, ax
0x13e98: cld
0x13e99: rep stosd dword ptr es:[di], eax
0x13e9b: ret
0x13e9c: add byte ptr [bx + si], al
0x13e9e: add byte ptr [bx + si], al
0x13ea0: add byte ptr [bx + si], al
0x13ea2: add byte ptr [bx + si], al
0x13ea4: add byte ptr [bx + si], al
0x13ea6: add byte ptr [bx + si], al
0x13ea8: add byte ptr [bx + si], al
2018-12-17T23:04:58.441448024Z 48 PC: 13714 | Get DOS version
2018-12-17T23:04:58.443200109Z 41 PC: 13024 | Parse filename
2018-12-17T23:04:58.445283938Z 41 PC: 13032 | Parse filename
2018-12-17T23:04:58.447515014Z 75 PC: 1303d | Execute program
2018-12-17T23:04:58.47234572Z 80 PC: 180a9 | Set current PSP
2018-12-17T23:04:58.473421764Z 48 PC: 180ae | Get DOS version
2018-12-17T23:04:58.476504962Z 99 PC: 1e890 | Get DBCS lead byte table pointer
2018-12-17T23:04:58.47977929Z 101 PC: 18134 | Get extended country info
2018-12-17T23:04:58.481575297Z 99 PC: 1813a | Get DBCS lead byte table pointer
2018-12-17T23:04:58.484409157Z 74 PC: 1819c | Reallocate memory
2018-12-17T23:04:58.486408547Z 25 PC: 181d3 | Get default drive
2018-12-17T23:04:58.488070763Z 37 PC: 17c93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:04:58.490383712Z 37 PC: 17c9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:58.49171204Z 37 PC: 17ca1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:58.496403854Z 74 PC: 16e3c | Reallocate memory
2018-12-17T23:04:58.4988371Z 72 PC: 16e7d | Allocate memory
2018-12-17T23:04:58.50085257Z 72 PC: 16eb5 | Allocate memory
2018-12-17T23:04:58.503117018Z 72 PC: 16ebd | Allocate memory