Sample viewer

vx.netlux.org/Virus.DOS.HLLC.10074

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:32.867718231Z 53 PC: 141da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:32.870150578Z 53 PC: 141da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:32.871726991Z 53 PC: 141da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:32.87316306Z 53 PC: 141da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:32.874607645Z 53 PC: 141da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:32.876610621Z 53 PC: 141da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:32.878109318Z 53 PC: 141da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:32.879553136Z 53 PC: 141da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:32.881952051Z 53 PC: 141da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:32.883213718Z 53 PC: 141da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:32.884350564Z 53 PC: 141da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:32.885960974Z 53 PC: 141da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:32.887167671Z 53 PC: 141da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:32.888800909Z 53 PC: 141da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:32.89107101Z 53 PC: 141da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:32.892477865Z 53 PC: 141da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:32.893801672Z 53 PC: 141da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:32.895622789Z 53 PC: 141da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:32.896926786Z 53 PC: 141da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:32.89807943Z 37 PC: 141ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:32.899561507Z 37 PC: 141f7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:32.90059448Z 37 PC: 141ff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:32.901653424Z 37 PC: 14207 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:32.904026216Z 68 PC: 15a18 | I/O control for devices (Set for = '�ذ��G�')
2018-12-17T23:08:32.906333957Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:32.907824133Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:32.909322253Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:32.911105753Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:32.912786352Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:32.914775792Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:32.916663079Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:32.918147087Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:32.920400374Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:32.921833854Z 37 PC: 14bc0 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:32.923171516Z 37 PC: 14bc7 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:32.925421959Z 37 PC: 14bce | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:32.927503778Z 37 PC: 14bd5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:33.041588139Z 37 PC: 13991 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:33.043029785Z 44 PC: 15b4f | Get time 0x15b4f: mov word ptr [0x340], cx
0x15b53: mov word ptr [0x342], dx
0x15b57: retf
0x15b58: mov cx, di
0x15b5a: mov si, 0xa
0x15b5d: mov bx, dx
0x15b5f: or bx, bx
0x15b61: jns 0x15b74
0x15b63: neg bx
0x15b65: neg ax
0x15b67: sbb bx, 0
0x15b6a: call 0x15b74
0x15b6d: dec di
0x15b6e: mov byte ptr es:[di], 0x2d
0x15b72: inc cx
0x15b73: ret
0x15b74: xor dx, dx
0x15b76: xchg ax, bx
0x15b77: div si
0x15b79: xchg ax, bx
2018-12-17T23:08:33.045602736Z 48 PC: 15543 | Get DOS version
2018-12-17T23:08:33.046970951Z 61 PC: 15381 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:08:33.053706315Z 66 PC: 15c9c | Move file pointer
2018-12-17T23:08:33.055815368Z 66 PC: 15caa | Move file pointer
2018-12-17T23:08:33.057261029Z 66 PC: 15cb8 | Move file pointer
2018-12-17T23:08:33.05886951Z 62 PC: 153d1 | Close file
2018-12-17T23:08:33.061552295Z 48 PC: 15543 | Get DOS version
2018-12-17T23:08:33.063719741Z 26 PC: 13fe9 | Set disk transfer address
2018-12-17T23:08:33.065001738Z 78 PC: 13ff5 | Find first file
2018-12-17T23:08:33.079477606Z 25 PC: 155d0 | Get default drive
2018-12-17T23:08:33.080519587Z 71 PC: 155e3 | Get current directory
2018-12-17T23:08:33.083411123Z 59 PC: 15697 | Change current directory
2018-12-17T23:08:33.088247518Z 26 PC: 13fe9 | Set disk transfer address
2018-12-17T23:08:33.089359306Z 78 PC: 13ff5 | Find first file
2018-12-17T23:08:33.095228566Z 26 PC: 13fe9 | Set disk transfer address
2018-12-17T23:08:33.096798266Z 78 PC: 13ff5 | Find first file
2018-12-17T23:08:33.102686376Z 48 PC: 15543 | Get DOS version
2018-12-17T23:08:33.104934883Z 26 PC: 13fe9 | Set disk transfer address
2018-12-17T23:08:33.107754774Z 78 PC: 13ff5 | Find first file
2018-12-17T23:08:33.11354786Z 26 PC: 1400d | Set disk transfer address
2018-12-17T23:08:33.114465276Z 79 PC: 14012 | Find next file
2018-12-17T23:08:33.117163797Z 48 PC: 15543 | Get DOS version
2018-12-17T23:08:33.118639545Z 14 PC: 15629 | Set default drive (Drive = 'A')
2018-12-17T23:08:33.119711011Z 25 PC: 1562d | Get default drive
2018-12-17T23:08:33.121627237Z 59 PC: 15697 | Change current directory
2018-12-17T23:08:33.125609786Z 37 PC: 14331 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:33.126560216Z 37 PC: 14331 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:33.12812387Z 37 PC: 14331 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:33.129149647Z 37 PC: 14331 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:33.130142246Z 37 PC: 14331 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:33.132103555Z 37 PC: 14331 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:33.133139386Z 37 PC: 14331 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:33.134130706Z 37 PC: 14331 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:33.136014014Z 37 PC: 14331 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:33.13701807Z 37 PC: 14331 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:33.138021299Z 37 PC: 14331 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:33.13986165Z 37 PC: 14331 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:33.140940048Z 37 PC: 14331 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:33.141941172Z 37 PC: 14331 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:33.143111921Z 37 PC: 14331 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:33.154272612Z 37 PC: 14331 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:33.155263201Z 37 PC: 14331 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:33.156774972Z 37 PC: 14331 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:33.158003871Z 37 PC: 14331 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:33.15921894Z 76 PC: 14370 | Terminate with return code (Return code = '0')