Sample viewer

vx.netlux.org/Virus.DOS.HLLC.14795

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:09.455664528Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:10:09.457856798Z 74 PC: 12abc | Reallocate memory
2018-12-17T23:10:09.460323685Z 48 PC: 13062 | Get DOS version
2018-12-17T23:10:09.462032246Z 53 PC: 12b2f | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:09.4643384Z 37 PC: 12b41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:09.465862454Z 68 PC: 12be8 | I/O control for devices (Set for = '')
2018-12-17T23:10:09.467519668Z 68 PC: 12be8 | I/O control for devices
2018-12-17T23:10:09.469908998Z 68 PC: 12be8 | I/O control for devices
2018-12-17T23:10:09.471546416Z 68 PC: 12be8 | I/O control for devices
2018-12-17T23:10:09.473387376Z 68 PC: 12be8 | I/O control for devices
2018-12-17T23:10:09.477811109Z 42 PC: 136fa | Get date 0x136fa: mov bx, dx
0x136fc: mov si, cx
0x136fe: mov ah, 0x2c
0x13700: int 0x21
0x13702: mov ah, 0
0x13704: mov al, dh
0x13706: push ax
0x13707: mov al, cl
0x13709: push ax
0x1370a: mov al, ch
0x1370c: push ax
0x1370d: push ax
0x1370e: mov ah, 0x2a
0x13710: int 0x21
0x13712: cmp bx, dx
0x13714: pop ax
0x13715: je 0x1371f
0x13717: cmp al, 0x17
0x13719: jne 0x1371f
0x1371b: mov dx, bx
2018-12-17T23:10:09.484458923Z 44 PC: 13702 | Get time 0x13702: mov ah, 0
0x13704: mov al, dh
0x13706: push ax
0x13707: mov al, cl
0x13709: push ax
0x1370a: mov al, ch
0x1370c: push ax
0x1370d: push ax
0x1370e: mov ah, 0x2a
0x13710: int 0x21
0x13712: cmp bx, dx
0x13714: pop ax
0x13715: je 0x1371f
0x13717: cmp al, 0x17
0x13719: jne 0x1371f
0x1371b: mov dx, bx
0x1371d: mov cx, si
0x1371f: mov ah, 0
0x13721: mov al, dl
0x13723: push ax
2018-12-17T23:10:09.487183744Z 42 PC: 13712 | Get date 0x13712: cmp bx, dx
0x13714: pop ax
0x13715: je 0x1371f
0x13717: cmp al, 0x17
0x13719: jne 0x1371f
0x1371b: mov dx, bx
0x1371d: mov cx, si
0x1371f: mov ah, 0
0x13721: mov al, dl
0x13723: push ax
0x13724: mov al, dh
0x13726: push ax
0x13727: sub cx, 0x7bc
0x1372b: push cx
0x1372c: call 0x1439a
0x1372f: add sp, 0xc
0x13732: cmp word ptr [bp + 4], 0
0x13736: je 0x13740
0x13738: mov bx, word ptr [bp + 4]
0x1373b: mov word ptr [bx + 2], dx
2018-12-17T23:10:09.492764742Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.49474857Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.496120117Z 78 PC: 13940 | Find first file
2018-12-17T23:10:09.506022928Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.50830143Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.509634956Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.510976908Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.514967368Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.517158957Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.518903275Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.521527206Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.525211089Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.527233861Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.52955875Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.531215052Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.534975089Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.538664422Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.540064594Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.541444106Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.545525526Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.547346919Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.548584405Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.550329134Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.555251094Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.55742532Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.559017021Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.561494577Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.568124557Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.569707583Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.57193072Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.573498807Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.577067975Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.579956253Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.581570116Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.583212833Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.58754811Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.58962862Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.59129941Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.593146492Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.596760394Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.598605802Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.600161645Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.602785266Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.606387596Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.608361466Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.610504032Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.612009612Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.6154942Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.618305694Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.61961241Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.620858221Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.625335195Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.626927928Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.62811061Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.630788754Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.634039914Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.635659558Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.637389008Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.638706203Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.645642899Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.647385645Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.649360015Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.650569608Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.653778318Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.656465769Z 47 PC: 1392e | Get disk transfer address
2018-12-17T23:10:09.657784026Z 26 PC: 13932 | Set disk transfer address
2018-12-17T23:10:09.658925051Z 79 PC: 13940 | Find next file
2018-12-17T23:10:09.662632529Z 26 PC: 1394d | Set disk transfer address
2018-12-17T23:10:09.665382747Z 61 PC: 14ad8 | Open file (Filename = 'C:\DOS\CHKDSK.COM')
2018-12-17T23:10:09.675625637Z 41 PC: 153e7 | Parse filename
2018-12-17T23:10:09.677957459Z 41 PC: 153ef | Parse filename
2018-12-17T23:10:09.679595698Z 11 PC: 15439 | Get input status
2018-12-17T23:10:09.68259829Z 75 PC: 15447 | Execute program
2018-12-17T23:10:09.707949674Z 80 PC: 24029 | Set current PSP
2018-12-17T23:10:09.709096569Z 48 PC: 2402e | Get DOS version
2018-12-17T23:10:09.710915548Z 99 PC: 2a810 | Get DBCS lead byte table pointer
2018-12-17T23:10:09.714680563Z 101 PC: 240b4 | Get extended country info
2018-12-17T23:10:09.716352706Z 99 PC: 240ba | Get DBCS lead byte table pointer
2018-12-17T23:10:09.718134906Z 74 PC: 2411c | Reallocate memory
2018-12-17T23:10:09.72088329Z 25 PC: 24153 | Get default drive
2018-12-17T23:10:09.722942761Z 37 PC: 23c13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:10:09.724622858Z 37 PC: 23c1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:09.727340596Z 37 PC: 23c21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:09.732383894Z 74 PC: 22dbc | Reallocate memory
2018-12-17T23:10:09.734392188Z 72 PC: 22dfd | Allocate memory
2018-12-17T23:10:09.73652721Z 72 PC: 22e35 | Allocate memory
2018-12-17T23:10:09.739757722Z 72 PC: 22e3d | Allocate memory