Sample viewer

vx.netlux.org/Virus.DOS.HLLP.BJVC.4725

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:22.167244139Z 53 PC: 131ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.168916138Z 53 PC: 131ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:22.171405118Z 53 PC: 131ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:22.173123702Z 53 PC: 131ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:22.174731091Z 53 PC: 131ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.178867577Z 53 PC: 131ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.180071651Z 53 PC: 131ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:22.181140075Z 53 PC: 131ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:22.183126678Z 53 PC: 131ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:22.185039038Z 53 PC: 131ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:22.18846363Z 53 PC: 131ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:22.191291322Z 53 PC: 131ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:22.194319471Z 53 PC: 131ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:22.195563735Z 53 PC: 131ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:22.197246979Z 53 PC: 131ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:22.198449284Z 53 PC: 131ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:22.199533401Z 53 PC: 131ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:22.200836255Z 53 PC: 131ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.206122128Z 53 PC: 131ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:22.207386814Z 37 PC: 131df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.208748674Z 37 PC: 131e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.210555946Z 37 PC: 131ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.212817218Z 37 PC: 131f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.216369942Z 68 PC: 13a55 | I/O control for devices (Set for = '')
2018-12-17T23:09:22.219117011Z 42 PC: 12f76 | Get date 0x12f76: mov byte ptr [0x56], dh
0x12f7a: mov byte ptr [0x57], dl
0x12f7e: mov di, 0x59
0x12f81: push ds
0x12f82: push di
0x12f83: call 0x22a40
0x12f86: cmp byte ptr [0x57], 0x17
0x12f8b: mov al, 0
0x12f8d: jne 0x12f90
0x12f8f: inc ax
0x12f90: mov dl, al
0x12f92: cmp byte ptr [0x56], 8
0x12f97: mov al, 0
0x12f99: jne 0x12f9c
0x12f9b: inc ax
0x12f9c: and al, dl
0x12f9e: or al, al
0x12fa0: je 0x12fb0
0x12fa2: mov ah, 0x40
0x12fa4: mov bx, 1
2018-12-17T23:09:22.221943798Z 48 PC: 13780 | Get DOS version
2018-12-17T23:09:22.223618183Z 48 PC: 13780 | Get DOS version
2018-12-17T23:09:22.232813871Z 61 PC: 13632 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:09:22.240592891Z 63 PC: 13705 | Read file or device (Read 4720 bytes on handle 5)
2018-12-17T23:09:22.249141909Z 62 PC: 13682 | Close file
2018-12-17T23:09:22.252372378Z 26 PC: 13047 | Set disk transfer address
2018-12-17T23:09:22.253929361Z 78 PC: 13053 | Find first file
2018-12-17T23:09:22.261496341Z 61 PC: 13632 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:09:22.270446121Z 66 PC: 13764 | Move file pointer
2018-12-17T23:09:22.272888182Z 63 PC: 13705 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T23:09:22.28117068Z 26 PC: 1306b | Set disk transfer address
2018-12-17T23:09:22.283754282Z 79 PC: 13070 | Find next file
2018-12-17T23:09:22.286909735Z 48 PC: 13780 | Get DOS version
2018-12-17T23:09:22.288746324Z 26 PC: 13047 | Set disk transfer address
2018-12-17T23:09:22.290512356Z 78 PC: 13053 | Find first file
2018-12-17T23:09:22.298535061Z 48 PC: 13780 | Get DOS version
2018-12-17T23:09:22.300186554Z 67 PC: 13016 | Get or set file attributes
2018-12-17T23:09:22.31805101Z 61 PC: 13632 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:09:22.326288607Z 66 PC: 13764 | Move file pointer
2018-12-17T23:09:22.328025742Z 63 PC: 13705 | Read file or device (Read 4720 bytes on handle 6)
2018-12-17T23:09:22.336927381Z 66 PC: 13764 | Move file pointer
2018-12-17T23:09:22.339262682Z 64 PC: 13663 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:09:22.347770825Z 66 PC: 13764 | Move file pointer
2018-12-17T23:09:22.350029703Z 64 PC: 13705 | Write file or device (Write 4720 bytes on handle 6)
2018-12-17T23:09:22.360073566Z 62 PC: 13682 | Close file
2018-12-17T23:09:22.367380304Z 53 PC: 13148 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.36850129Z 37 PC: 13151 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.370514911Z 53 PC: 13148 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:22.371647628Z 37 PC: 13151 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:22.372841142Z 53 PC: 13148 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:22.374392586Z 37 PC: 13151 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:22.3754418Z 53 PC: 13148 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:22.376729237Z 37 PC: 13151 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:22.378019443Z 53 PC: 13148 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.379187736Z 37 PC: 13151 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.38010462Z 53 PC: 13148 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.381028912Z 37 PC: 13151 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.38241709Z 53 PC: 13148 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:22.383311346Z 37 PC: 13151 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:22.384183964Z 53 PC: 13148 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:22.385699798Z 37 PC: 13151 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:22.387013166Z 53 PC: 13148 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:22.388297656Z 37 PC: 13151 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:22.390247404Z 53 PC: 13148 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:22.39223688Z 37 PC: 13151 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:22.393256703Z 53 PC: 13148 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:22.394800676Z 37 PC: 13151 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:22.395853874Z 53 PC: 13148 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:22.397288219Z 37 PC: 13151 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:22.398683204Z 53 PC: 13148 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:22.399938187Z 37 PC: 13151 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:22.400941288Z 53 PC: 13148 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:22.402167074Z 37 PC: 13151 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:22.403486547Z 53 PC: 13148 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:22.404501863Z 37 PC: 13151 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:22.405573898Z 53 PC: 13148 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:22.407106398Z 37 PC: 13151 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:22.408324645Z 53 PC: 13148 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:22.40934117Z 37 PC: 13151 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:22.410923972Z 53 PC: 13148 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.412014914Z 37 PC: 13151 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.413195054Z 53 PC: 13148 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:22.414660533Z 37 PC: 13151 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:22.416002086Z 41 PC: 130ff | Parse filename
2018-12-17T23:09:22.41718313Z 41 PC: 1310d | Parse filename
2018-12-17T23:09:22.422016392Z 75 PC: 13118 | Execute program
2018-12-17T23:09:22.432126783Z 9 PC: 171f8 | Display string (Could not find end pointer)
2018-12-17T23:09:22.440053108Z 76 PC: 171fc | Terminate with return code (Return code = '36')
2018-12-17T23:09:22.443001753Z 53 PC: 13148 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.44404943Z 37 PC: 13151 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.445105262Z 53 PC: 13148 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:22.446567908Z 37 PC: 13151 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:22.447793892Z 53 PC: 13148 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:22.449214021Z 37 PC: 13151 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:22.450867186Z 53 PC: 13148 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:22.453055492Z 37 PC: 13151 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:22.4589229Z 53 PC: 13148 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.460991689Z 37 PC: 13151 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.462673254Z 53 PC: 13148 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.464913952Z 37 PC: 13151 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.466652386Z 53 PC: 13148 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:22.467705621Z 37 PC: 13151 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:22.468699411Z 53 PC: 13148 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:22.470267315Z 37 PC: 13151 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:22.47136515Z 53 PC: 13148 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:22.472800949Z 37 PC: 13151 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:22.474689879Z 53 PC: 13148 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:22.47590912Z 37 PC: 13151 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:22.477170845Z 53 PC: 13148 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:22.478763824Z 37 PC: 13151 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:22.480094469Z 53 PC: 13148 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:22.481181046Z 37 PC: 13151 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:22.483227817Z 53 PC: 13148 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:22.484507402Z 37 PC: 13151 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:22.486070956Z 53 PC: 13148 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:22.488322445Z 37 PC: 13151 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:22.489863764Z 53 PC: 13148 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:22.491235967Z 37 PC: 13151 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:22.493393238Z 53 PC: 13148 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:22.494841629Z 37 PC: 13151 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:22.49624483Z 53 PC: 13148 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:22.498635689Z 37 PC: 13151 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:22.500372488Z 53 PC: 13148 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.502160466Z 37 PC: 13151 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.504591218Z 53 PC: 13148 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:22.506174142Z 37 PC: 13151 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:22.507691362Z 48 PC: 13780 | Get DOS version
2018-12-17T23:09:22.510461855Z 67 PC: 13016 | Get or set file attributes
2018-12-17T23:09:22.540108864Z 61 PC: 13632 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:09:22.548499072Z 64 PC: 13705 | Write file or device (Write 4720 bytes on handle 6)
2018-12-17T23:09:22.558220211Z 66 PC: 13764 | Move file pointer
2018-12-17T23:09:22.561690312Z 64 PC: 13705 | Write file or device (Write 4720 bytes on handle 6)
2018-12-17T23:09:22.571503132Z 66 PC: 13764 | Move file pointer
2018-12-17T23:09:22.573205881Z 64 PC: 13705 | Write file or device (Write 5 bytes on handle 6)
2018-12-17T23:09:22.576826641Z 62 PC: 13682 | Close file
2018-12-17T23:09:22.586519709Z 64 PC: 1358d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:09:22.588606876Z 37 PC: 13321 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:22.590006435Z 37 PC: 13321 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:22.591248331Z 37 PC: 13321 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:22.59247283Z 37 PC: 13321 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:22.594287942Z 37 PC: 13321 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:22.595509694Z 37 PC: 13321 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:22.596736883Z 37 PC: 13321 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:22.59849193Z 37 PC: 13321 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:22.59967677Z 37 PC: 13321 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:22.601297674Z 37 PC: 13321 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:22.603137177Z 37 PC: 13321 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:22.604389093Z 37 PC: 13321 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:22.605569412Z 37 PC: 13321 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:22.607296194Z 37 PC: 13321 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:22.608461734Z 37 PC: 13321 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:22.609698488Z 37 PC: 13321 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:22.611308548Z 37 PC: 13321 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:22.612412369Z 37 PC: 13321 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:22.61357818Z 37 PC: 13321 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:22.615841655Z 76 PC: 13360 | Terminate with return code (Return code = '0')