Sample viewer

vx.netlux.org/Virus.DOS.HLLW.Ehhehe.31107

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:04:49.274629586Z 48 PC: 1829c | Get DOS version
2018-12-17T22:04:49.276457503Z 74 PC: 182ec | Reallocate memory
2018-12-17T22:04:49.278505171Z 48 PC: 18350 | Get DOS version
2018-12-17T22:04:49.279923985Z 53 PC: 18358 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:49.282361493Z 37 PC: 1836a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:49.284244872Z 53 PC: 1b1a2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:49.285689112Z 37 PC: 1b1b2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:49.287436665Z 53 PC: 1b1b7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:49.289034533Z 37 PC: 1b1c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:49.290194728Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:49.291647964Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:49.293487296Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:49.29454519Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:49.29578652Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:49.297188618Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:49.298319616Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:49.299617686Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:49.300958064Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:49.30213931Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:49.303489538Z 53 PC: 18ef6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:04:49.306074688Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:49.30716368Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:49.308419466Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:49.310044842Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:49.311136044Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:49.312410838Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:49.313743536Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:49.315042229Z 37 PC: 18f25 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:49.316864203Z 37 PC: 18f2c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:49.318960754Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:49.320688462Z 68 PC: 183fb | I/O control for devices (Set for = 'ˉ3SJ3[V&;wr&;wr &+wr&;wr@^Ñq 3;r;wHP ')
2018-12-17T22:04:49.322452924Z 68 PC: 183fb | I/O control for devices (Set for = 'prtvxz|~')
2018-12-17T22:04:49.324895676Z 68 PC: 183fb | I/O control for devices (Set for = '')
2018-12-17T22:04:49.326673872Z 68 PC: 183fb | I/O control for devices (Set for = 'D 3rD\l|3?I|at+@}[0~ t 3߃0s t&')
2018-12-17T22:04:49.328357181Z 68 PC: 183fb | I/O control for devices (Set for = 'D 3rD\l|3?I|at+@}[0~ t 3߃0s t&')
2018-12-17T22:04:49.331390461Z 53 PC: 15768 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:49.332594387Z 53 PC: 15775 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:04:49.334440035Z 53 PC: 15782 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:49.33611676Z 37 PC: 15797 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:49.337647389Z 37 PC: 1579f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:04:49.33914273Z 37 PC: 157a7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:49.344488239Z 53 PC: 16226 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:04:49.346053514Z 53 PC: 16233 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:04:49.347563265Z 53 PC: 16242 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:49.349446564Z 37 PC: 1624f | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:04:49.350581565Z 53 PC: 16256 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:49.356712375Z 37 PC: 16263 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:04:49.358617982Z 53 PC: 1626f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:04:49.36290988Z 48 PC: 16331 | Get DOS version
2018-12-17T22:04:49.364361527Z 74 PC: 14433 | Reallocate memory
2018-12-17T22:04:49.366636263Z 74 PC: 14433 | Reallocate memory
2018-12-17T22:04:49.368202013Z 68 PC: 156de | I/O control for devices (Set for = 'd files 0%')
2018-12-17T22:04:49.369902759Z 68 PC: 156de | I/O control for devices (Set for = '')
2018-12-17T22:04:49.372073586Z 51 PC: 156fc | Get or set Ctrl-Break
2018-12-17T22:04:49.372873932Z 51 PC: 15708 | Get or set Ctrl-Break
2018-12-17T22:04:49.381325548Z 74 PC: 14433 | Reallocate memory
2018-12-17T22:04:49.383676727Z 51 PC: 15713 | Get or set Ctrl-Break
2018-12-17T22:04:49.384441788Z 37 PC: 15995 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:49.385421959Z 37 PC: 1599f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:04:49.393936674Z 37 PC: 159a9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:49.395222075Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:49.396253714Z 53 PC: 13e6d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:04:49.39813154Z 53 PC: 13e7a | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:49.3992871Z 37 PC: 13e95 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:04:49.401551028Z 53 PC: 13e9d | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:04:49.403290968Z 37 PC: 13eaa | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:49.404205092Z 53 PC: 13eb1 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:04:49.405838769Z 37 PC: 13ebe | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:49.407757813Z 37 PC: 13ec8 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:04:49.41035344Z 37 PC: 13ed3 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:04:49.411479393Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:49.413656839Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:49.41487728Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:49.416176061Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:49.418241572Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:49.419594026Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:49.420901429Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:49.423016092Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:49.425074817Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:49.426592931Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:49.428390423Z 37 PC: 18f41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:04:49.429872459Z 37 PC: 1b1d6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:49.432495836Z 37 PC: 184ac | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:49.436643072Z 41 PC: 1806d | Parse filename
2018-12-17T22:04:49.438411711Z 41 PC: 1806f | Parse filename
2018-12-17T22:04:49.439736846Z 41 PC: 18074 | Parse filename
2018-12-17T22:04:49.441530714Z 75 PC: 1808a | Execute program
2018-12-17T22:04:49.461944224Z 80 PC: 1e1a9 | Set current PSP
2018-12-17T22:04:49.464712213Z 48 PC: 1e1ae | Get DOS version
2018-12-17T22:04:49.466774972Z 99 PC: 24990 | Get DBCS lead byte table pointer
2018-12-17T22:04:49.469270504Z 101 PC: 1e234 | Get extended country info
2018-12-17T22:04:49.470405029Z 99 PC: 1e23a | Get DBCS lead byte table pointer
2018-12-17T22:04:49.472376373Z 74 PC: 1e29c | Reallocate memory
2018-12-17T22:04:49.473667627Z 25 PC: 1e2d3 | Get default drive
2018-12-17T22:04:49.474673668Z 37 PC: 1dd93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:04:49.476177794Z 37 PC: 1dd9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:49.477211756Z 37 PC: 1dda1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:49.487936454Z 74 PC: 1cf3c | Reallocate memory
2018-12-17T22:04:49.489778945Z 72 PC: 1cf7d | Allocate memory
2018-12-17T22:04:49.491516003Z 72 PC: 1cfb5 | Allocate memory
2018-12-17T22:04:49.493354274Z 72 PC: 1cfbd | Allocate memory