Sample viewer

vx.netlux.org/Virus.DOS.HLLC.5376

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:59.533765789Z 53 PC: 1312a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:59.535783942Z 53 PC: 1312a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:59.551204185Z 53 PC: 1312a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:59.555122479Z 53 PC: 1312a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:59.556590007Z 53 PC: 1312a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:59.559196747Z 53 PC: 1312a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:59.560729006Z 53 PC: 1312a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:59.562157551Z 53 PC: 1312a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:59.564324093Z 53 PC: 1312a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:59.566755303Z 53 PC: 1312a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:59.569110229Z 53 PC: 1312a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:59.57367087Z 53 PC: 1312a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:59.576401122Z 53 PC: 1312a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:59.578907553Z 53 PC: 1312a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:59.58172086Z 53 PC: 1312a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:59.583201493Z 53 PC: 1312a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:59.58462573Z 53 PC: 1312a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:59.586117374Z 53 PC: 1312a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:59.591035688Z 53 PC: 1312a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:59.592384883Z 37 PC: 1313f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:59.593510419Z 37 PC: 13147 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:59.595520046Z 37 PC: 1314f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:59.597741962Z 37 PC: 13157 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:59.600254344Z 68 PC: 13c87 | I/O control for devices (Set for = 't%�>\�.t�\����v�\����s �\���� ')
2018-12-17T23:08:59.603211983Z 48 PC: 139b2 | Get DOS version
2018-12-17T23:08:59.604847807Z 48 PC: 139b2 | Get DOS version
2018-12-17T23:08:59.607439208Z 48 PC: 139b2 | Get DOS version
2018-12-17T23:08:59.611476085Z 60 PC: 137f0 | Create or truncate file
2018-12-17T23:08:59.633437501Z 65 PC: 13939 | Delete file (Filename = '�')
2018-12-17T23:08:59.644962442Z 26 PC: 12f35 | Set disk transfer address
2018-12-17T23:08:59.646934258Z 78 PC: 12f41 | Find first file
2018-12-17T23:08:59.652190477Z 26 PC: 12f35 | Set disk transfer address
2018-12-17T23:08:59.653278743Z 78 PC: 12f41 | Find first file
2018-12-17T23:08:59.659037847Z 86 PC: 1397d | Rename file
2018-12-17T23:08:59.669968862Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:59.671213721Z 37 PC: 130ad | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:59.672970724Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:59.674806143Z 37 PC: 130ad | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:59.676515155Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:59.678889207Z 37 PC: 130ad | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:59.680180815Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:59.681500044Z 37 PC: 130ad | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:59.68301408Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:59.684627933Z 37 PC: 130ad | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:59.68586581Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:59.687081435Z 37 PC: 130ad | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:59.689879073Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:59.69104793Z 37 PC: 130ad | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:59.692168045Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:59.69421402Z 37 PC: 130ad | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:59.695637405Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:59.697098191Z 37 PC: 130ad | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:59.699072612Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:59.700512538Z 37 PC: 130ad | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:59.701929141Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:59.704733652Z 37 PC: 130ad | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:59.706987328Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:59.70912234Z 37 PC: 130ad | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:59.711526699Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:59.713464331Z 37 PC: 130ad | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:59.7154059Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:59.71778407Z 37 PC: 130ad | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:59.720767026Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:59.722179411Z 37 PC: 130ad | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:59.724396969Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:59.725952322Z 37 PC: 130ad | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:59.729322596Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:59.731425529Z 37 PC: 130ad | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:59.733929966Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:59.735562084Z 37 PC: 130ad | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:59.737112648Z 53 PC: 130a4 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:59.739719678Z 37 PC: 130ad | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:59.741602236Z 41 PC: 1305b | Parse filename
2018-12-17T23:08:59.745027935Z 41 PC: 13069 | Parse filename
2018-12-17T23:08:59.747666163Z 75 PC: 13074 | Execute program
2018-12-17T23:08:59.785810977Z 80 PC: 16269 | Set current PSP
2018-12-17T23:08:59.78711077Z 48 PC: 1626e | Get DOS version
2018-12-17T23:08:59.790666703Z 99 PC: 1ca50 | Get DBCS lead byte table pointer
2018-12-17T23:08:59.793882427Z 101 PC: 162f4 | Get extended country info
2018-12-17T23:08:59.795855626Z 99 PC: 162fa | Get DBCS lead byte table pointer
2018-12-17T23:08:59.797786685Z 74 PC: 1635c | Reallocate memory
2018-12-17T23:08:59.800130901Z 25 PC: 16393 | Get default drive
2018-12-17T23:08:59.801932317Z 37 PC: 15e53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:08:59.803648923Z 37 PC: 15e5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:59.805439058Z 37 PC: 15e61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:59.809949094Z 74 PC: 14ffc | Reallocate memory
2018-12-17T23:08:59.811304592Z 72 PC: 1503d | Allocate memory
2018-12-17T23:08:59.814215282Z 72 PC: 15075 | Allocate memory
2018-12-17T23:08:59.816368169Z 72 PC: 1507d | Allocate memory