Sample viewer

vx.netlux.org/Virus.DOS.HLLC.4496

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:56.06601213Z 53 PC: 130aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:56.067500844Z 53 PC: 130aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:56.06852153Z 53 PC: 130aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:56.069588904Z 53 PC: 130aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:56.071546543Z 53 PC: 130aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:56.072853906Z 53 PC: 130aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:56.073856228Z 53 PC: 130aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:56.075301899Z 53 PC: 130aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:56.07634176Z 53 PC: 130aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:56.07734585Z 53 PC: 130aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:56.078579969Z 53 PC: 130aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:56.085136432Z 53 PC: 130aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:56.086604099Z 53 PC: 130aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:56.088535361Z 53 PC: 130aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:56.093102028Z 53 PC: 130aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:56.094147522Z 53 PC: 130aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:56.09515859Z 53 PC: 130aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:56.096438123Z 53 PC: 130aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:56.097589502Z 53 PC: 130aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:56.09874124Z 37 PC: 130bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:56.117498247Z 37 PC: 130c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:56.118483398Z 37 PC: 130cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:56.119349862Z 37 PC: 130d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:56.121140436Z 68 PC: 13995 | I/O control for devices (Set for = '')
2018-12-17T23:06:56.122294792Z 48 PC: 136bb | Get DOS version
2018-12-17T23:06:56.123716092Z 48 PC: 136bb | Get DOS version
2018-12-17T23:06:56.125287647Z 61 PC: 1356d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:06:56.131725186Z 63 PC: 13640 | Read file or device (Read 4496 bytes on handle 5)
2018-12-17T23:06:56.138656374Z 62 PC: 135bd | Close file
2018-12-17T23:06:56.141496754Z 26 PC: 12ef7 | Set disk transfer address
2018-12-17T23:06:56.142443211Z 78 PC: 12f03 | Find first file
2018-12-17T23:06:56.150057326Z 61 PC: 1356d | Open file (Filename = 'TEST.COM')
2018-12-17T23:06:56.15640064Z 60 PC: 1356d | Create or truncate file
2018-12-17T23:06:56.172969087Z 64 PC: 13640 | Write file or device (Write 4496 bytes on handle 5)
2018-12-17T23:06:56.181663086Z 67 PC: 12e9f | Get or set file attributes
2018-12-17T23:06:56.187990037Z 67 PC: 12ec6 | Get or set file attributes
2018-12-17T23:06:56.198212326Z 61 PC: 1356d | Open file (Filename = 'TEST.EXE')
2018-12-17T23:06:56.204756257Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.214000936Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.216884041Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.218345406Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.222504701Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.224153882Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.226757971Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.230206177Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.232712725Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.234192364Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.237345319Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.238689971Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.241029389Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.242621626Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.249203364Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.250489781Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.253469386Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.254791003Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.257118127Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.259313447Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.263710956Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.267671769Z 63 PC: 13640 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T23:06:56.270612096Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.272062141Z 63 PC: 13640 | Read file or device (Read 2000 bytes on handle 6)
2018-12-17T23:06:56.279259402Z 66 PC: 1369f | Move file pointer
2018-12-17T23:06:56.28106269Z 64 PC: 13640 | Write file or device (Write 2000 bytes on handle 6)
2018-12-17T23:06:56.289094275Z 62 PC: 135bd | Close file
2018-12-17T23:06:56.296841506Z 67 PC: 12ec6 | Get or set file attributes
2018-12-17T23:06:56.311297485Z 62 PC: 135bd | Close file
2018-12-17T23:06:56.316342016Z 26 PC: 12f1b | Set disk transfer address
2018-12-17T23:06:56.31720118Z 79 PC: 12f20 | Find next file
2018-12-17T23:06:56.322003231Z 64 PC: 134c8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:06:56.32329902Z 37 PC: 13201 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:56.32412124Z 37 PC: 13201 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:56.325236015Z 37 PC: 13201 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:56.32664879Z 37 PC: 13201 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:56.327955374Z 37 PC: 13201 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:56.329921782Z 37 PC: 13201 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:56.330886088Z 37 PC: 13201 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:56.331821856Z 37 PC: 13201 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:56.333190507Z 37 PC: 13201 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:56.334203584Z 37 PC: 13201 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:56.335213292Z 37 PC: 13201 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:56.336363516Z 37 PC: 13201 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:56.337864029Z 37 PC: 13201 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:56.338991719Z 37 PC: 13201 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:56.340228565Z 37 PC: 13201 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:56.343757779Z 37 PC: 13201 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:56.344821598Z 37 PC: 13201 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:56.346130629Z 37 PC: 13201 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:56.347399613Z 37 PC: 13201 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:56.3484023Z 76 PC: 13240 | Terminate with return code (Return code = '0')