Sample viewer

vx.netlux.org/Virus.DOS.HLLC.IMP.4790

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:28.194513101Z 53 PC: 1331a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.196396938Z 53 PC: 1331a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:28.202425333Z 53 PC: 1331a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.203543385Z 53 PC: 1331a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:28.204628991Z 53 PC: 1331a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.206386312Z 53 PC: 1331a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.207466137Z 53 PC: 1331a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:28.208510083Z 53 PC: 1331a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:28.210180344Z 53 PC: 1331a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:28.211254468Z 53 PC: 1331a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:28.212350182Z 53 PC: 1331a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:28.214793863Z 53 PC: 1331a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:28.21588937Z 53 PC: 1331a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:28.216971273Z 53 PC: 1331a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:28.218622734Z 53 PC: 1331a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:28.220019403Z 53 PC: 1331a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:28.22127727Z 53 PC: 1331a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:28.23612369Z 53 PC: 1331a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.237570957Z 53 PC: 1331a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:28.239003133Z 37 PC: 1332f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.240574004Z 37 PC: 13337 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.241860129Z 37 PC: 1333f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.242934242Z 37 PC: 13347 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.244453486Z 68 PC: 13f31 | I/O control for devices (Set for = '')
2018-12-17T23:08:28.246076247Z 48 PC: 13b47 | Get DOS version
2018-12-17T23:08:28.247477126Z 26 PC: 130ad | Set disk transfer address
2018-12-17T23:08:28.248413013Z 78 PC: 130b9 | Find first file
2018-12-17T23:08:28.255066449Z 26 PC: 130d1 | Set disk transfer address
2018-12-17T23:08:28.256860143Z 79 PC: 130d6 | Find next file
2018-12-17T23:08:28.260206174Z 26 PC: 130ad | Set disk transfer address
2018-12-17T23:08:28.261844961Z 78 PC: 130b9 | Find first file
2018-12-17T23:08:28.268729284Z 65 PC: 13ace | Delete file (Filename = 'antivir.dat')
2018-12-17T23:08:28.275151496Z 65 PC: 13ace | Delete file (Filename = 'chklist.ms')
2018-12-17T23:08:28.281577367Z 65 PC: 13ace | Delete file (Filename = 'chklist.cps')
2018-12-17T23:08:28.287305575Z 67 PC: 1300f | Get or set file attributes
2018-12-17T23:08:28.292856517Z 67 PC: 13036 | Get or set file attributes
2018-12-17T23:08:28.502064889Z 61 PC: 13985 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:08:28.509309422Z 87 PC: 13050 | Get or set file date and time
2018-12-17T23:08:28.511280699Z 62 PC: 139d5 | Close file
2018-12-17T23:08:28.514857466Z 86 PC: 13b12 | Rename file
2018-12-17T23:08:28.530681459Z 61 PC: 13985 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:08:28.537950793Z 60 PC: 13985 | Create or truncate file
2018-12-17T23:08:28.550254171Z 61 PC: 13985 | Open file (Filename = '_TEST.EXE')
2018-12-17T23:08:28.556774198Z 66 PC: 14030 | Move file pointer
2018-12-17T23:08:28.558343503Z 66 PC: 1403e | Move file pointer
2018-12-17T23:08:28.560570727Z 66 PC: 1404c | Move file pointer
2018-12-17T23:08:28.562414233Z 64 PC: 13a58 | Write file or device (Write 6080 bytes on handle 5)
2018-12-17T23:08:28.571052481Z 87 PC: 1307d | Get or set file date and time
2018-12-17T23:08:28.573571858Z 87 PC: 1307d | Get or set file date and time
2018-12-17T23:08:28.575389043Z 87 PC: 13050 | Get or set file date and time
2018-12-17T23:08:28.577159549Z 87 PC: 1307d | Get or set file date and time
2018-12-17T23:08:28.579888134Z 87 PC: 13050 | Get or set file date and time
2018-12-17T23:08:28.581735528Z 87 PC: 1307d | Get or set file date and time
2018-12-17T23:08:28.583284915Z 62 PC: 139d5 | Close file
2018-12-17T23:08:28.591860832Z 87 PC: 13050 | Get or set file date and time
2018-12-17T23:08:28.593624747Z 87 PC: 1307d | Get or set file date and time
2018-12-17T23:08:28.595167578Z 62 PC: 139d5 | Close file
2018-12-17T23:08:28.6027544Z 67 PC: 13036 | Get or set file attributes
2018-12-17T23:08:28.613679162Z 67 PC: 13036 | Get or set file attributes
2018-12-17T23:08:28.62398434Z 53 PC: 13292 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.626174276Z 37 PC: 1329b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.627386048Z 53 PC: 13292 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:28.628643335Z 37 PC: 1329b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:28.630612689Z 53 PC: 13292 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.631807712Z 37 PC: 1329b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.632836368Z 53 PC: 13292 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:28.634585023Z 37 PC: 1329b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:28.635711043Z 53 PC: 13292 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.636804621Z 37 PC: 1329b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.638512766Z 53 PC: 13292 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.639636238Z 37 PC: 1329b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.640667002Z 53 PC: 13292 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:28.641914743Z 37 PC: 1329b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:28.643366035Z 53 PC: 13292 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:28.644393838Z 37 PC: 1329b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:28.645434827Z 53 PC: 13292 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:28.646878985Z 37 PC: 1329b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:28.647943682Z 53 PC: 13292 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:28.649036029Z 37 PC: 1329b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:28.650750801Z 53 PC: 13292 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:28.651778193Z 37 PC: 1329b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:28.652816172Z 53 PC: 13292 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:28.654597285Z 37 PC: 1329b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:28.65561913Z 53 PC: 13292 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:28.656732467Z 37 PC: 1329b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:28.658362597Z 53 PC: 13292 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:28.659680879Z 37 PC: 1329b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:28.661025304Z 53 PC: 13292 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:28.666958819Z 37 PC: 1329b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:28.668344815Z 53 PC: 13292 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:28.66976399Z 37 PC: 1329b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:28.672000164Z 53 PC: 13292 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:28.673727796Z 37 PC: 1329b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:28.675084542Z 53 PC: 13292 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.677226264Z 37 PC: 1329b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.678313156Z 53 PC: 13292 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:28.681121876Z 37 PC: 1329b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:28.684243917Z 41 PC: 131e1 | Parse filename
2018-12-17T23:08:28.686507374Z 41 PC: 131ef | Parse filename
2018-12-17T23:08:28.687941951Z 75 PC: 131fa | Execute program
2018-12-17T23:08:28.717179686Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.718506954Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:28.719809146Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:28.722559676Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:28.723751704Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.724819539Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.725962481Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:28.72756054Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:28.728824142Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:28.730105776Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:28.732020805Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:28.733353142Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:28.734670594Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:28.736951205Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:28.738179723Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:28.739381634Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:28.741676734Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:28.7428489Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.744034566Z 53 PC: 24b4a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:28.74641572Z 37 PC: 24b5f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:28.747652274Z 37 PC: 24b67 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:28.748876783Z 37 PC: 24b6f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:28.750557336Z 37 PC: 24b77 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:28.752087261Z 68 PC: 25761 | I/O control for devices (Set for = '')
2018-12-17T23:08:28.753689664Z 48 PC: 25377 | Get DOS version
2018-12-17T23:08:28.755812678Z 26 PC: 248dd | Set disk transfer address
2018-12-17T23:08:28.75703455Z 78 PC: 248e9 | Find first file
2018-12-17T23:08:28.763374616Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.765094022Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.767706249Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.768679825Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.776734287Z 26 PC: 248dd | Set disk transfer address
2018-12-17T23:08:28.778746078Z 78 PC: 248e9 | Find first file
2018-12-17T23:08:28.785225952Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.789309203Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.792510829Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.794304916Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.798448792Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.799505567Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.80243212Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.804977289Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.807988667Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.809208875Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.812644913Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.813886949Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.816888709Z 26 PC: 24901 | Set disk transfer address
2018-12-17T23:08:28.818527836Z 79 PC: 24906 | Find next file
2018-12-17T23:08:28.821545084Z 64 PC: 24f0d | Write file or device (Write 25 bytes on handle 1)
2018-12-17T23:08:28.82651024Z 64 PC: 24f0d | Write file or device (Write 30 bytes on handle 1)