Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Duke.4336

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:46.126634354Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:46.128153804Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:07:46.130232995Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:07:46.131619882Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:46.133074084Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:07:46.135665851Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:46.138163327Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:07:46.140609551Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:07:46.152005495Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:07:46.153712142Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:07:46.155383483Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:07:46.158027603Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:07:46.159637505Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:07:46.161358733Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:07:46.17435885Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:07:46.182675101Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:07:46.183790827Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:07:46.18488922Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:07:46.198400921Z 53 PC: 12f1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:07:46.200352368Z 37 PC: 12f2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:46.202374176Z 37 PC: 12f37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:07:46.205360308Z 37 PC: 12f3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:46.207826899Z 37 PC: 12f47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:07:46.210728984Z 68 PC: 138bf | I/O control for devices (Set for = '')
2018-12-17T23:07:46.213544782Z 48 PC: 134d0 | Get DOS version
2018-12-17T23:07:46.223647419Z 61 PC: 13382 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:07:46.232879891Z 63 PC: 13455 | Read file or device (Read 4336 bytes on handle 5)
2018-12-17T23:07:46.242023129Z 66 PC: 139be | Move file pointer
2018-12-17T23:07:46.243765694Z 66 PC: 139cc | Move file pointer
2018-12-17T23:07:46.245417002Z 66 PC: 139da | Move file pointer
2018-12-17T23:07:46.247810876Z 26 PC: 12dc7 | Set disk transfer address
2018-12-17T23:07:46.249231506Z 78 PC: 12dd3 | Find first file
2018-12-17T23:07:46.256250466Z 26 PC: 12deb | Set disk transfer address
2018-12-17T23:07:46.258347664Z 79 PC: 12df0 | Find next file
2018-12-17T23:07:46.261497056Z 64 PC: 132dd | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:07:46.263834337Z 37 PC: 13071 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:46.266379007Z 37 PC: 13071 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:07:46.26792985Z 37 PC: 13071 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:07:46.26939718Z 37 PC: 13071 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:46.271963977Z 37 PC: 13071 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:07:46.273375643Z 37 PC: 13071 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:46.274784031Z 37 PC: 13071 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:07:46.276151446Z 37 PC: 13071 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:07:46.278497275Z 37 PC: 13071 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:07:46.28096091Z 37 PC: 13071 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:07:46.28261669Z 37 PC: 13071 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:07:46.284693024Z 37 PC: 13071 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:07:46.286064791Z 37 PC: 13071 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:07:46.287302544Z 37 PC: 13071 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:07:46.289063311Z 37 PC: 13071 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:07:46.291048467Z 37 PC: 13071 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:07:46.292818496Z 37 PC: 13071 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:07:46.295233297Z 37 PC: 13071 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:07:46.297030624Z 37 PC: 13071 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:07:46.29895839Z 76 PC: 130b0 | Terminate with return code (Return code = '0')