Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Duke.4528

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:44.363166194Z 53 PC: 12fca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:44.364811829Z 53 PC: 12fca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:44.366135944Z 53 PC: 12fca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:44.367184377Z 53 PC: 12fca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:44.373008874Z 53 PC: 12fca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:44.374911349Z 53 PC: 12fca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:44.376780069Z 53 PC: 12fca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:44.383993914Z 53 PC: 12fca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:44.386019718Z 53 PC: 12fca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:44.388092387Z 53 PC: 12fca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:44.390791894Z 53 PC: 12fca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:44.392081849Z 53 PC: 12fca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:44.393274595Z 53 PC: 12fca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:44.395064789Z 53 PC: 12fca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:44.39648041Z 53 PC: 12fca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:44.397835667Z 53 PC: 12fca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:44.401778333Z 53 PC: 12fca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:44.402885378Z 53 PC: 12fca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:44.403805996Z 53 PC: 12fca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:44.405630796Z 37 PC: 12fdf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:44.407361353Z 37 PC: 12fe7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:44.408733877Z 37 PC: 12fef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:44.410978455Z 37 PC: 12ff7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:44.412972319Z 68 PC: 13929 | I/O control for devices (Set for = '')
2018-12-17T23:09:44.415033919Z 48 PC: 1364f | Get DOS version
2018-12-17T23:09:44.417301895Z 61 PC: 1348d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:09:44.430482983Z 63 PC: 13560 | Read file or device (Read 4528 bytes on handle 5)
2018-12-17T23:09:44.438072932Z 62 PC: 134dd | Close file
2018-12-17T23:09:44.440904218Z 61 PC: 1348d | Open file (Filename = 'A:\TEST.DAT')
2018-12-17T23:09:44.448685774Z 26 PC: 12e17 | Set disk transfer address
2018-12-17T23:09:44.451312892Z 78 PC: 12e23 | Find first file
2018-12-17T23:09:44.458858273Z 61 PC: 1348d | Open file (Filename = 'TEST.DAT')
2018-12-17T23:09:44.466315018Z 67 PC: 12de6 | Get or set file attributes
2018-12-17T23:09:44.481141741Z 86 PC: 1361a | Rename file
2018-12-17T23:09:44.492955782Z 60 PC: 1348d | Create or truncate file
2018-12-17T23:09:44.504555991Z 64 PC: 13560 | Write file or device (Write 4528 bytes on handle 5)
2018-12-17T23:09:44.513399954Z 62 PC: 134dd | Close file
2018-12-17T23:09:44.521345793Z 26 PC: 12e3b | Set disk transfer address
2018-12-17T23:09:44.523432986Z 79 PC: 12e40 | Find next file
2018-12-17T23:09:44.526873579Z 61 PC: 1348d | Open file (Filename = 'TEST.DAT')
2018-12-17T23:09:44.533571023Z 62 PC: 134dd | Close file
2018-12-17T23:09:44.535898139Z 26 PC: 12e3b | Set disk transfer address
2018-12-17T23:09:44.537547801Z 79 PC: 12e40 | Find next file
2018-12-17T23:09:44.544041425Z 64 PC: 133e8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:09:44.54589314Z 37 PC: 13121 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:44.547436947Z 37 PC: 13121 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:44.548545329Z 37 PC: 13121 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:44.549665859Z 37 PC: 13121 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:44.55227071Z 37 PC: 13121 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:44.554060631Z 37 PC: 13121 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:44.555790785Z 37 PC: 13121 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:44.558480971Z 37 PC: 13121 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:44.560198464Z 37 PC: 13121 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:44.561368609Z 37 PC: 13121 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:44.563292522Z 37 PC: 13121 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:44.56474671Z 37 PC: 13121 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:44.566185659Z 37 PC: 13121 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:44.568141469Z 37 PC: 13121 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:44.569261233Z 37 PC: 13121 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:44.570368192Z 37 PC: 13121 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:44.572037653Z 37 PC: 13121 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:44.573455745Z 37 PC: 13121 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:44.574488289Z 37 PC: 13121 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:44.576536005Z 76 PC: 13160 | Terminate with return code (Return code = '0')