Sample viewer

vx.netlux.org/Virus.DOS.HLLP.4156

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:29.01844347Z 53 PC: 133ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:29.020331553Z 53 PC: 133ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:29.022049935Z 53 PC: 133ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:29.023277485Z 53 PC: 133ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:29.025674892Z 53 PC: 133ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:29.027111034Z 53 PC: 133ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.028308985Z 53 PC: 133ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:29.029523994Z 53 PC: 133ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:29.031772122Z 53 PC: 133ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:29.03344529Z 53 PC: 133ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:29.034659325Z 53 PC: 133ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:29.037584433Z 53 PC: 133ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:29.038791009Z 53 PC: 133ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:29.039997788Z 53 PC: 133ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:29.041994416Z 53 PC: 133ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:29.04420185Z 53 PC: 133ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:29.046342145Z 53 PC: 133ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:29.05375183Z 53 PC: 133ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:29.05555934Z 53 PC: 133ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:29.057489374Z 37 PC: 133df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:29.059641326Z 37 PC: 133e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:29.062118285Z 37 PC: 133ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.063243934Z 37 PC: 133f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:29.065648718Z 68 PC: 13e39 | I/O control for devices (Set for = '')
2018-12-17T23:06:29.068694151Z 26 PC: 1316d | Set disk transfer address
2018-12-17T23:06:29.071232485Z 78 PC: 13179 | Find first file
2018-12-17T23:06:29.07758779Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.084092335Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.087469447Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.088627311Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.092309602Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.093295162Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.096276337Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.110227966Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.113555319Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.114528817Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.117785921Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.11871205Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.121893328Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.123379263Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.126697942Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.127956262Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.132728678Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.133899284Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.137613202Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.139620823Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.144568463Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.146080493Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.151165698Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.152671286Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.156601119Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.158700506Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.16274362Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.163766196Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.167500984Z 61 PC: 1388d | Open file (Filename = '\TEST.EXE')
2018-12-17T23:06:29.173860519Z 67 PC: 130cf | Get or set file attributes
2018-12-17T23:06:29.179246119Z 87 PC: 13110 | Get or set file date and time
2018-12-17T23:06:29.181769672Z 66 PC: 139bf | Move file pointer
2018-12-17T23:06:29.183303171Z 63 PC: 13960 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:06:29.18962648Z 67 PC: 130f6 | Get or set file attributes
2018-12-17T23:06:29.202554535Z 87 PC: 1313d | Get or set file date and time
2018-12-17T23:06:29.204221085Z 62 PC: 138dd | Close file
2018-12-17T23:06:29.211321639Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.21336465Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.216659834Z 26 PC: 1316d | Set disk transfer address
2018-12-17T23:06:29.218026902Z 78 PC: 13179 | Find first file
2018-12-17T23:06:29.225159026Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.22627415Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.228755042Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.230421394Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.232904802Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.233839739Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.237395136Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.238452244Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.241079468Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.243136103Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.245620548Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.246550904Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.249816505Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.250712777Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.25316315Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.255466096Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.258250113Z 26 PC: 13191 | Set disk transfer address
2018-12-17T23:06:29.259453633Z 79 PC: 13196 | Find next file
2018-12-17T23:06:29.262537032Z 48 PC: 13a4f | Get DOS version
2018-12-17T23:06:29.264215405Z 61 PC: 1388d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:06:29.270582011Z 67 PC: 130cf | Get or set file attributes
2018-12-17T23:06:29.2769019Z 87 PC: 13110 | Get or set file date and time
2018-12-17T23:06:29.278293904Z 66 PC: 13f38 | Move file pointer
2018-12-17T23:06:29.279484559Z 66 PC: 13f46 | Move file pointer
2018-12-17T23:06:29.28125904Z 66 PC: 13f54 | Move file pointer
2018-12-17T23:06:29.282905212Z 63 PC: 13960 | Read file or device (Read 4156 bytes on handle 5)
2018-12-17T23:06:29.29045673Z 66 PC: 139bf | Move file pointer
2018-12-17T23:06:29.292265412Z 63 PC: 13960 | Read file or device (Read 4156 bytes on handle 5)
2018-12-17T23:06:29.299613737Z 66 PC: 139bf | Move file pointer
2018-12-17T23:06:29.30145361Z 64 PC: 13960 | Write file or device (Write 4156 bytes on handle 5)
2018-12-17T23:06:29.311035148Z 66 PC: 139bf | Move file pointer
2018-12-17T23:06:29.312386204Z 64 PC: 138be | Write file or device (Write 0 bytes on handle 5)
2018-12-17T23:06:29.320163833Z 62 PC: 138dd | Close file
2018-12-17T23:06:29.328399584Z 53 PC: 13340 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:29.32954675Z 37 PC: 13349 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:29.330754996Z 53 PC: 13340 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:29.3326551Z 37 PC: 13349 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:29.333782214Z 53 PC: 13340 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:29.334884137Z 37 PC: 13349 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:29.337155288Z 53 PC: 13340 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:29.338252469Z 37 PC: 13349 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:29.339418637Z 53 PC: 13340 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:29.34108695Z 37 PC: 13349 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:29.342149998Z 53 PC: 13340 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.343287497Z 37 PC: 13349 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.344925755Z 53 PC: 13340 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:29.345998434Z 37 PC: 13349 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:29.347119297Z 53 PC: 13340 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:29.348874821Z 37 PC: 13349 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:29.34994337Z 53 PC: 13340 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:29.350990009Z 37 PC: 13349 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:29.352802126Z 53 PC: 13340 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:29.35398971Z 37 PC: 13349 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:29.355223021Z 53 PC: 13340 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:29.357070168Z 37 PC: 13349 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:29.358319951Z 53 PC: 13340 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:29.359584175Z 37 PC: 13349 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:29.361743076Z 53 PC: 13340 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:29.36306408Z 37 PC: 13349 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:29.364342024Z 53 PC: 13340 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:29.366573416Z 37 PC: 13349 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:29.367872892Z 53 PC: 13340 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:29.369287879Z 37 PC: 13349 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:29.370886707Z 53 PC: 13340 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:29.373367443Z 37 PC: 13349 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:29.375077852Z 53 PC: 13340 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:29.37694526Z 37 PC: 13349 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:29.378405237Z 53 PC: 13340 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:29.379528767Z 37 PC: 13349 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:29.381858517Z 53 PC: 13340 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:29.383344083Z 37 PC: 13349 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:29.385139009Z 48 PC: 13a4f | Get DOS version
2018-12-17T23:06:29.388107878Z 41 PC: 132f7 | Parse filename
2018-12-17T23:06:29.389644004Z 41 PC: 13305 | Parse filename
2018-12-17T23:06:29.391601962Z 75 PC: 13310 | Execute program
2018-12-17T23:06:29.412044481Z 80 PC: 1d759 | Set current PSP
2018-12-17T23:06:29.413527504Z 48 PC: 1d75e | Get DOS version
2018-12-17T23:06:29.415226891Z 99 PC: 23f40 | Get DBCS lead byte table pointer
2018-12-17T23:06:29.418167757Z 101 PC: 1d7e4 | Get extended country info
2018-12-17T23:06:29.420607432Z 99 PC: 1d7ea | Get DBCS lead byte table pointer
2018-12-17T23:06:29.421944906Z 74 PC: 1d84c | Reallocate memory
2018-12-17T23:06:29.423486105Z 25 PC: 1d883 | Get default drive
2018-12-17T23:06:29.425195765Z 37 PC: 1d343 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:06:29.426193105Z 37 PC: 1d34a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:29.427178608Z 37 PC: 1d351 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:29.43181706Z 74 PC: 1c4ec | Reallocate memory
2018-12-17T23:06:29.433232387Z 72 PC: 1c52d | Allocate memory
2018-12-17T23:06:29.435006368Z 72 PC: 1c565 | Allocate memory
2018-12-17T23:06:29.437271457Z 72 PC: 1c56d | Allocate memory