Sample viewer

vx.netlux.org/Virus.DOS.HLLP.7353

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:53.104968662Z 53 PC: 1406a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:53.10783497Z 53 PC: 1406a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:53.109239753Z 53 PC: 1406a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:53.110622026Z 53 PC: 1406a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:53.11257689Z 53 PC: 1406a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:53.11443134Z 53 PC: 1406a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:53.116153443Z 53 PC: 1406a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:53.118287513Z 53 PC: 1406a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:53.119433641Z 53 PC: 1406a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:53.121149223Z 53 PC: 1406a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:53.125540799Z 53 PC: 1406a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:53.127266053Z 53 PC: 1406a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:53.128870243Z 53 PC: 1406a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:53.130441383Z 53 PC: 1406a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:53.131769486Z 53 PC: 1406a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:53.132941043Z 53 PC: 1406a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:53.134454649Z 53 PC: 1406a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:53.136334077Z 53 PC: 1406a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:53.137493312Z 53 PC: 1406a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:53.138696933Z 37 PC: 1407f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:53.141067014Z 37 PC: 14087 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:53.142446462Z 37 PC: 1408f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:53.143834936Z 37 PC: 14097 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:53.146690381Z 68 PC: 14e52 | I/O control for devices (Set for = '�6���/<�t=')
2018-12-17T23:09:53.278979259Z 37 PC: 137f1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:53.281681727Z 48 PC: 14982 | Get DOS version
2018-12-17T23:09:53.286237855Z 48 PC: 14982 | Get DOS version
2018-12-17T23:09:53.288404567Z 53 PC: 13fda | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:53.290141838Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:53.292569241Z 53 PC: 13fda | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:53.294281877Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:53.296006781Z 53 PC: 13fda | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:53.306355644Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:53.307876999Z 53 PC: 13fda | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:53.309386127Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:53.311691986Z 53 PC: 13fda | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:53.313865712Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:53.315929018Z 53 PC: 13fda | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:53.317709551Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:53.320679337Z 53 PC: 13fda | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:53.321895811Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:53.323077619Z 53 PC: 13fda | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:53.324961191Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:53.326831507Z 53 PC: 13fda | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:53.328161585Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:53.330187034Z 53 PC: 13fda | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:53.331902859Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:53.333569603Z 53 PC: 13fda | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:53.335814127Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:53.33732174Z 53 PC: 13fda | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:53.338998456Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:53.341600971Z 53 PC: 13fda | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:53.343391585Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:53.345050214Z 53 PC: 13fda | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:53.347526008Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:53.349006317Z 53 PC: 13fda | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:53.350899201Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:53.353865748Z 53 PC: 13fda | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:53.35544008Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:53.356938507Z 53 PC: 13fda | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:53.358795628Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:53.361739178Z 53 PC: 13fda | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:53.364199363Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:53.366131606Z 53 PC: 13fda | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:53.368467223Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:53.370399948Z 41 PC: 13f91 | Parse filename
2018-12-17T23:09:53.372452267Z 41 PC: 13f9f | Parse filename
2018-12-17T23:09:53.374809199Z 75 PC: 13faa | Execute program
2018-12-17T23:09:53.400436524Z 80 PC: 22169 | Set current PSP
2018-12-17T23:09:53.401406814Z 48 PC: 2216e | Get DOS version
2018-12-17T23:09:53.404126353Z 99 PC: 28950 | Get DBCS lead byte table pointer
2018-12-17T23:09:53.407488494Z 101 PC: 221f4 | Get extended country info
2018-12-17T23:09:53.409354897Z 99 PC: 221fa | Get DBCS lead byte table pointer
2018-12-17T23:09:53.412287092Z 74 PC: 2225c | Reallocate memory
2018-12-17T23:09:53.414302319Z 25 PC: 22293 | Get default drive
2018-12-17T23:09:53.415962646Z 37 PC: 21d53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:09:53.418511597Z 37 PC: 21d5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:53.423385564Z 37 PC: 21d61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:53.428731456Z 74 PC: 20efc | Reallocate memory
2018-12-17T23:09:53.431714309Z 72 PC: 20f3d | Allocate memory
2018-12-17T23:09:53.433882075Z 72 PC: 20f75 | Allocate memory
2018-12-17T23:09:53.436163083Z 72 PC: 20f7d | Allocate memory