Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5192

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:05.647426751Z 53 PC: 1357a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:05.65294767Z 53 PC: 1357a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:05.654154143Z 53 PC: 1357a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:05.655283035Z 53 PC: 1357a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:05.656984811Z 53 PC: 1357a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:05.658000864Z 53 PC: 1357a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:05.658996917Z 53 PC: 1357a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:05.660436169Z 53 PC: 1357a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:05.661522177Z 53 PC: 1357a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:05.662567446Z 53 PC: 1357a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:05.664042121Z 53 PC: 1357a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:05.665042807Z 53 PC: 1357a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:05.666183419Z 53 PC: 1357a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:05.667680793Z 53 PC: 1357a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:05.668668188Z 53 PC: 1357a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:05.669648882Z 53 PC: 1357a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:05.671019057Z 53 PC: 1357a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:05.671851819Z 53 PC: 1357a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:05.67268747Z 53 PC: 1357a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:05.674226389Z 37 PC: 1358f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:05.675036662Z 37 PC: 13597 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:05.676224337Z 37 PC: 1359f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:05.677237007Z 37 PC: 135a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:05.67841462Z 68 PC: 141dd | I/O control for devices (Set for = '')
2018-12-17T23:10:05.6799129Z 26 PC: 1337d | Set disk transfer address
2018-12-17T23:10:05.681079391Z 78 PC: 13389 | Find first file
2018-12-17T23:10:05.684584399Z 67 PC: 13306 | Get or set file attributes
2018-12-17T23:10:05.687649146Z 61 PC: 13ca0 | Open file (Filename = 'C:\DO\')
2018-12-17T23:10:05.691460472Z 67 PC: 13306 | Get or set file attributes
2018-12-17T23:10:05.694602184Z 26 PC: 133a1 | Set disk transfer address
2018-12-17T23:10:05.695908541Z 79 PC: 133a6 | Find next file
2018-12-17T23:10:05.699526115Z 26 PC: 1337d | Set disk transfer address
2018-12-17T23:10:05.700381974Z 78 PC: 13389 | Find first file
2018-12-17T23:10:05.704110052Z 67 PC: 13306 | Get or set file attributes
2018-12-17T23:10:06.640915432Z 61 PC: 13ca0 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:10:06.648935266Z 62 PC: 13cf0 | Close file
2018-12-17T23:10:06.651436014Z 67 PC: 13306 | Get or set file attributes
2018-12-17T23:10:06.792144289Z 26 PC: 133a1 | Set disk transfer address
2018-12-17T23:10:06.793446711Z 79 PC: 133a6 | Find next file
2018-12-17T23:10:06.795462753Z 48 PC: 13dee | Get DOS version
2018-12-17T23:10:06.796807725Z 67 PC: 132df | Get or set file attributes
2018-12-17T23:10:06.801282264Z 67 PC: 13306 | Get or set file attributes
2018-12-17T23:10:06.81607353Z 61 PC: 13ca0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:06.823022028Z 87 PC: 13320 | Get or set file date and time
2018-12-17T23:10:06.825273253Z 66 PC: 142dc | Move file pointer
2018-12-17T23:10:06.82668983Z 66 PC: 142ea | Move file pointer
2018-12-17T23:10:06.828037443Z 66 PC: 142f8 | Move file pointer
2018-12-17T23:10:06.83044797Z 63 PC: 13d73 | Read file or device (Read 5191 bytes on handle 5)
2018-12-17T23:10:06.837924144Z 63 PC: 13d73 | Read file or device (Read 101 bytes on handle 5)
2018-12-17T23:10:06.840721405Z 62 PC: 13cf0 | Close file
2018-12-17T23:10:06.845002478Z 48 PC: 13dee | Get DOS version
2018-12-17T23:10:06.846506668Z 60 PC: 13ca0 | Create or truncate file
2018-12-17T23:10:06.861071325Z 64 PC: 13d73 | Write file or device (Write 101 bytes on handle 5)
2018-12-17T23:10:06.866660355Z 62 PC: 13cf0 | Close file
2018-12-17T23:10:06.87495809Z 53 PC: 134ec | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:06.876788485Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:06.883087348Z 53 PC: 134ec | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:06.88468407Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:06.886141325Z 53 PC: 134ec | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:06.887917619Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:06.888970059Z 53 PC: 134ec | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:06.8902001Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:06.892364227Z 53 PC: 134ec | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:06.893559989Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:06.894875941Z 53 PC: 134ec | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:06.897052882Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:06.898359693Z 53 PC: 134ec | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:06.899681959Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:06.901585879Z 53 PC: 134ec | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:06.902878683Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:06.904198261Z 53 PC: 134ec | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:06.906204578Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:06.907547436Z 53 PC: 134ec | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:06.90888095Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:06.910849528Z 53 PC: 134ec | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:06.912284061Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:06.913688548Z 53 PC: 134ec | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:06.916555579Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:06.918123546Z 53 PC: 134ec | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:06.919284426Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:06.921608243Z 53 PC: 134ec | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:06.923143773Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:06.924453089Z 53 PC: 134ec | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:06.926197737Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:06.927197451Z 53 PC: 134ec | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:06.928217273Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:06.929949604Z 53 PC: 134ec | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:06.931392599Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:06.93254409Z 53 PC: 134ec | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:06.934463922Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:06.935927554Z 53 PC: 134ec | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:06.937443055Z 37 PC: 134f5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:06.939591711Z 48 PC: 13dee | Get DOS version
2018-12-17T23:10:06.941339596Z 41 PC: 134a3 | Parse filename
2018-12-17T23:10:06.943122263Z 41 PC: 134b1 | Parse filename
2018-12-17T23:10:06.945911307Z 75 PC: 134bc | Execute program