Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Rock.8875

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:51.233978108Z 53 PC: 15eca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:51.235686041Z 53 PC: 15eca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:51.236980993Z 53 PC: 15eca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:51.244397017Z 53 PC: 15eca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:51.24652456Z 53 PC: 15eca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:51.248162742Z 53 PC: 15eca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:51.26154379Z 53 PC: 15eca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:51.263576493Z 53 PC: 15eca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:51.265586509Z 53 PC: 15eca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:51.272846607Z 53 PC: 15eca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:51.274895739Z 53 PC: 15eca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:51.276864443Z 53 PC: 15eca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:51.278682509Z 53 PC: 15eca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:51.279820672Z 53 PC: 15eca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:51.280924886Z 53 PC: 15eca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:51.282613728Z 53 PC: 15eca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:51.284568336Z 53 PC: 15eca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:51.286506699Z 53 PC: 15eca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:51.289122748Z 53 PC: 15eca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:51.290206337Z 37 PC: 15edf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:51.291169869Z 37 PC: 15ee7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:51.292303452Z 37 PC: 15eef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:51.293665994Z 37 PC: 15ef7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:51.295997471Z 68 PC: 167f9 | I/O control for devices (Set for = '')
2018-12-17T23:09:51.410257695Z 37 PC: 157d1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:51.411631799Z 44 PC: 16930 | Get time 0x16930: mov word ptr [0x3e], cx
0x16934: mov word ptr [0x40], dx
0x16938: retf
0x16939: mov di, 0x52
0x1693c: push ds
0x1693d: pop es
0x1693e: mov cx, 0x27fe
0x16941: sub cx, di
0x16943: shr cx, 1
0x16945: xor ax, ax
0x16947: cld
0x16948: rep stosd dword ptr es:[di], eax
0x1694a: ret
0x1694b: add byte ptr [bx + si], al
0x1694d: add byte ptr [bx + si], al
0x1694f: add byte ptr [bx + si], al
0x16951: add byte ptr [bx + si], al
0x16953: add byte ptr [bx + si], al
0x16955: add byte ptr [bx + si], al
0x16957: add byte ptr [bx + si], al
2018-12-17T23:09:51.413581985Z 81 PC: 12a44 | Get current PSP
2018-12-17T23:09:51.415094668Z 61 PC: 141d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:09:51.419326844Z 63 PC: 141ae | Read file or device (Read 8875 bytes on handle 5)
2018-12-17T23:09:51.424140031Z 62 PC: 141fa | Close file
2018-12-17T23:09:51.426297901Z 86 PC: 14222 | Rename file
2018-12-17T23:09:51.438888082Z 60 PC: 1420a | Create or truncate file
2018-12-17T23:09:51.447346794Z 62 PC: 141fa | Close file
2018-12-17T23:09:51.453362195Z 61 PC: 14237 | Open file (Filename = 'PRYLYCWH.ONJ')
2018-12-17T23:09:51.457699389Z 61 PC: 14243 | Open file (Filename = '�7R- ��C2� OEljYE P0����������D�E=C=PHt =�t�� 2f')
2018-12-17T23:09:51.469423771Z 66 PC: 14253 | Move file pointer
2018-12-17T23:09:51.47166221Z 66 PC: 1425f | Move file pointer
2018-12-17T23:09:51.473171487Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.481840671Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.490927225Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.499458659Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.507157388Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.514352302Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.5221481Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.539275027Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.552303416Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.561291492Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.569134575Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.576566889Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.585101933Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.592367256Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.600214041Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.609006927Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.616402116Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.624185198Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.633410397Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.642565198Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.65039613Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.658846709Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.667619264Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.676040913Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.684952261Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.69282515Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.700681939Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.709402975Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.717468018Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.725877138Z 64 PC: 14277 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:09:51.735459079Z 63 PC: 1426e | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:09:51.742850073Z 64 PC: 14277 | Write file or device (Write 1024 bytes on handle 6)
2018-12-17T23:09:51.75055794Z 62 PC: 14283 | Close file
2018-12-17T23:09:51.753478417Z 62 PC: 1428a | Close file
2018-12-17T23:09:51.761271169Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:51.762535536Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:51.76461924Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:51.765889165Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:51.767217402Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:51.769454937Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:51.770570621Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:51.771694529Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:51.773483459Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:51.774869678Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:51.776182808Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:51.777978844Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:51.779422882Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:51.780767346Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:51.783224088Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:51.784596093Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:51.78639589Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:51.788747005Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:51.790085721Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:51.791438162Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:51.793849454Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:51.795159483Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:51.79645367Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:51.798250933Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:51.799763936Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:51.80108661Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:51.802960187Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:51.804126624Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:51.805208387Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:51.806873434Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:51.808166137Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:51.809528032Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:51.811465777Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:51.812810032Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:51.81413913Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:51.81628559Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:51.817608398Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:51.819695077Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:51.821670036Z 41 PC: 15df6 | Parse filename
2018-12-17T23:09:51.823072056Z 41 PC: 15e04 | Parse filename
2018-12-17T23:09:51.824602803Z 75 PC: 15e0f | Execute program
2018-12-17T23:09:51.842812112Z 9 PC: 1a31c | Display string (Could not find end pointer)
2018-12-17T23:09:51.848572334Z 76 PC: 1a321 | Terminate with return code (Return code = '0')
2018-12-17T23:09:51.852269688Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:51.853931554Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:51.855540655Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:51.858424001Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:51.859962121Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:51.862406512Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:51.86457774Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:51.866061184Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:51.867199019Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:51.869085887Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:51.870224853Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:51.871374505Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:51.873271793Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:51.874473845Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:51.875658533Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:51.877766136Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:51.878864667Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:51.879972868Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:51.881444266Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:51.882752369Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:51.883716262Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:51.885555823Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:51.886651997Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:51.887729325Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:51.890455377Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:51.891725115Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:51.893071676Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:51.895257953Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:51.89633015Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:51.897474118Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:51.89971926Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:51.90079589Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:51.902143551Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:51.904321732Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:51.905608354Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:51.90702326Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:51.90889246Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:51.909828221Z 37 PC: 15e48 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:51.911573425Z 65 PC: 141ed | Delete file (Filename = '�����uM�D$')
2018-12-17T23:09:51.924019252Z 86 PC: 14222 | Rename file
2018-12-17T23:09:51.935669336Z 53 PC: 15d5a | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T23:09:51.937371383Z 37 PC: 15d76 | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T23:09:51.939764785Z 49 PC: 15d91 | Terminate and stay resident (Return code = '0' | Memory size = '1926')