Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Remiz.8288

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:27.867572998Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:27.869956452Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:27.871524044Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:27.872913135Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:27.875112717Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:27.87697788Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:27.878694871Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:27.881692216Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:27.886523835Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:27.888286193Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:27.905913975Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:27.907927156Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:27.9095847Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:27.911984516Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:27.915088338Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:27.916435566Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:27.918020342Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:27.920772104Z 53 PC: 14e56 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:27.922277388Z 37 PC: 14e6b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:27.923766317Z 37 PC: 14e73 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:27.926084841Z 37 PC: 14e7b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:27.927478085Z 37 PC: 14e83 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:27.929352301Z 68 PC: 154e1 | I/O control for devices (Set for = '')
2018-12-17T23:08:28.008590145Z 37 PC: 14517 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.011324606Z 48 PC: 15a3d | Get DOS version
2018-12-17T23:08:28.01337947Z 53 PC: 14cac | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.01584772Z 37 PC: 14cc8 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.01731318Z 51 PC: 14b9b | Get or set Ctrl-Break
2018-12-17T23:08:28.01849919Z 48 PC: 15a3d | Get DOS version
2018-12-17T23:08:28.02044258Z 61 PC: 158ef | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:08:28.028583929Z 66 PC: 15a21 | Move file pointer
2018-12-17T23:08:28.030249049Z 63 PC: 159c2 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T23:08:28.037637238Z 62 PC: 1593f | Close file
2018-12-17T23:08:28.045481843Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.046896917Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:28.048240136Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.050662144Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.052138786Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.053532997Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:28.070129011Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:28.072532299Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:28.074430862Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:28.079980467Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:28.081666685Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:28.08341499Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:28.085878259Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:28.087843118Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:28.090010114Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:28.092593073Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:28.094085443Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.095579203Z 37 PC: 14f65 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:28.097286455Z 76 PC: 14fa4 | Terminate with return code (Return code = '8')