Sample viewer

vx.netlux.org/Virus.DOS.Lemming.2151

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:05.234453438Z 255 PC: 12a66 | UNKNOWN!
2018-12-17T23:06:05.23558934Z 82 PC: 12b57 | Get DOS internal pointers (SYSVARS)
2018-12-17T23:06:05.236655318Z 88 PC: 12a90 | case 0xGet or set allocation strateg:
2018-12-17T23:06:05.237677139Z 88 PC: 12a9a | case 0xGet or set allocation strateg:
2018-12-17T23:06:05.239865672Z 53 PC: 130e4 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:05.240883068Z 37 PC: 130f1 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:05.242021345Z 53 PC: 13117 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:06:05.243464618Z 37 PC: 13127 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:05.244552563Z 76 PC: 12a46 | Terminate with return code (Return code = '0')
2018-12-17T23:06:05.247635238Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:06:05.249131326Z 72 PC: 12174 | Allocate memory
2018-12-17T23:06:05.251740473Z 72 PC: 1218d | Allocate memory
2018-12-17T23:06:05.254311128Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:06:05.256001985Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:05.257618212Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.259941943Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.261291346Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.263841742Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.265218643Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.266982874Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.268861476Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.270771243Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.27195217Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.274393585Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.275665489Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.277966143Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.279351099Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.282910148Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.285036184Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.2871636Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.289575173Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.291425214Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.29283453Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.295602487Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.296819672Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.298467463Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.300262488Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.302237651Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.303561136Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.313924204Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.315228354Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.317101134Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.318674987Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.320481176Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.32186212Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.326014426Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.327345297Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.329130106Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.331175506Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.332979738Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.334127468Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.33664477Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.337781323Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.339752388Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.341435633Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.343578574Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.344970036Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.34761825Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.349027284Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.350850508Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.352903559Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.354777052Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.355875583Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.358541704Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.359966255Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.361677819Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.362977961Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.365222479Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.366378529Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.368061305Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.369875755Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.371377529Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.372478613Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.375046231Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.376171797Z 62 PC: 122ab | Close file
2018-12-17T23:06:05.378959927Z 99 PC: 994f7 | Get DBCS lead byte table pointer
2018-12-17T23:06:05.380737341Z 56 PC: 93d19 | Get or set country info
2018-12-17T23:06:05.382832974Z 64 PC: 99768 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:06:05.388149686Z 25 PC: 93d82 | Get default drive
2018-12-17T23:06:05.390832767Z 71 PC: 95ffd | Get current directory
2018-12-17T23:06:05.394918403Z 64 PC: 99768 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:06:05.398279447Z 2 PC: 95fd2 | Character output (Char = '3e')
2018-12-17T23:06:05.401316907Z 93 PC: 93e40 | File sharing functions
2018-12-17T23:06:05.403198393Z 93 PC: 93e47 | File sharing functions
2018-12-17T23:06:05.405171609Z 10 PC: 93e59 | Buffered keyboard input
2018-12-17T23:06:20.219524856Z 0 PC: 0 | Program terminate
2018-12-17T23:06:21.574086881Z 0 PC: 0 | Program terminate
2018-12-17T23:06:21.677609483Z 64 PC: 99768 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:06:21.683126293Z 41 PC: 93ece | Parse filename
2018-12-17T23:06:21.684843926Z 41 PC: 93f4f | Parse filename
2018-12-17T23:06:21.687054663Z 41 PC: 93f6c | Parse filename
2018-12-17T23:06:21.689135159Z 26 PC: 97417 | Set disk transfer address
2018-12-17T23:06:21.691966523Z 71 PC: 97613 | Get current directory
2018-12-17T23:06:21.704693105Z 78 PC: 9ee65 | Find first file
2018-12-17T23:06:21.714095582Z 47 PC: 9ee74 | Get disk transfer address
2018-12-17T23:06:21.715583739Z 71 PC: 9748c | Get current directory
2018-12-17T23:06:21.722839308Z 73 PC: 96b29 | Release memory
2018-12-17T23:06:21.725045681Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.726418236Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.728501421Z 61 PC: 9f17f | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T23:06:21.735785629Z 87 PC: 9f17f | Get or set file date and time
2018-12-17T23:06:21.737485253Z 66 PC: 9f17f | Move file pointer
2018-12-17T23:06:21.739900328Z 63 PC: 9f17f | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:06:21.746243127Z 66 PC: 9f17f | Move file pointer
2018-12-17T23:06:21.749143922Z 64 PC: 9f17f | Write file or device (Write 2151 bytes on handle 5)
2018-12-17T23:06:21.764658336Z 66 PC: 9f17f | Move file pointer
2018-12-17T23:06:21.766740906Z 64 PC: 9f17f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:06:21.773240559Z 87 PC: 9f17f | Get or set file date and time
2018-12-17T23:06:21.775885525Z 62 PC: 9f17f | Close file
2018-12-17T23:06:21.783940042Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.785436184Z 75 PC: 11821 | Execute program
2018-12-17T23:06:21.801808135Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T23:06:21.805779905Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T23:06:21.808885033Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:06:21.811162833Z 72 PC: 12174 | Allocate memory
2018-12-17T23:06:21.81292105Z 72 PC: 1218d | Allocate memory
2018-12-17T23:06:21.814450918Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:06:21.81620036Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:21.817320604Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.818520541Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.820397055Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.822028608Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.823001247Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.824835686Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.826056463Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.830295426Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.832074543Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.833571944Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.834619107Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.837120921Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.838417633Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.84094204Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.84309555Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.845101922Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.846466422Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.849453449Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.850870141Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.853220441Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.8555051Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.857567518Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.858986219Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.861862071Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.863568812Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.865666286Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.868638472Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.871100155Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.872600855Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.874676839Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.875770941Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.879145909Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.881702561Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.883588789Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.884965805Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.890035215Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.892183436Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.894227812Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.896353195Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.898352428Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.899878108Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.902851799Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.903958555Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.905668837Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.90741701Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.909279796Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.910642346Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.912659911Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.914151147Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.915849524Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.9180872Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.919936496Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.921140572Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.922926839Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.924808922Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.926598658Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.927976009Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.929860325Z 53 PC: 9f17f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.931265826Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.932884468Z 37 PC: 9f17f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:21.934140184Z 62 PC: 122ab | Close file
2018-12-17T23:06:21.936868829Z 99 PC: 994f7 | Get DBCS lead byte table pointer
2018-12-17T23:06:21.938130145Z 56 PC: 93d19 | Get or set country info
2018-12-17T23:06:21.942384612Z 64 PC: 99768 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:06:21.946698785Z 25 PC: 93d82 | Get default drive
2018-12-17T23:06:21.948424628Z 71 PC: 95ffd | Get current directory
2018-12-17T23:06:21.952558705Z 64 PC: 99768 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:06:21.955618221Z 2 PC: 95fd2 | Character output (Char = '3e')
2018-12-17T23:06:21.957634045Z 93 PC: 93e40 | File sharing functions
2018-12-17T23:06:21.960108804Z 93 PC: 93e47 | File sharing functions
2018-12-17T23:06:21.961734132Z 10 PC: 93e59 | Buffered keyboard input