Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3792.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:04:59.818666612Z 53 PC: 130fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:59.820695278Z 53 PC: 130fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:59.822508143Z 53 PC: 130fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:04:59.824246073Z 53 PC: 130fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:04:59.82659968Z 53 PC: 130fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:59.828507969Z 53 PC: 130fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:59.830002115Z 53 PC: 130fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:59.832815737Z 53 PC: 130fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:59.834056327Z 53 PC: 130fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:59.835191219Z 53 PC: 130fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:59.836382031Z 53 PC: 130fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:59.851843674Z 53 PC: 130fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:59.856302064Z 53 PC: 130fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:59.857466491Z 53 PC: 130fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:59.859195829Z 53 PC: 130fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:59.860276868Z 53 PC: 130fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:59.861435329Z 53 PC: 130fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:04:59.863324405Z 53 PC: 130fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:04:59.866151319Z 53 PC: 130fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:04:59.868133362Z 37 PC: 1310f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:59.878128941Z 37 PC: 13117 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:59.87923981Z 37 PC: 1311f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:59.880263004Z 37 PC: 13127 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:04:59.882960842Z 68 PC: 13af5 | I/O control for devices (Set for = '')
2018-12-17T22:04:59.884450583Z 51 PC: 12a8d | Get or set Ctrl-Break
2018-12-17T22:04:59.885465169Z 48 PC: 1370b | Get DOS version
2018-12-17T22:04:59.888752189Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:04:59.895111343Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:04:59.913883037Z 61 PC: 135bd | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:04:59.922281018Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 5)
2018-12-17T22:04:59.930639141Z 66 PC: 13bf4 | Move file pointer
2018-12-17T22:04:59.932450848Z 66 PC: 13c02 | Move file pointer
2018-12-17T22:04:59.935658825Z 66 PC: 13c10 | Move file pointer
2018-12-17T22:04:59.93756528Z 66 PC: 136ef | Move file pointer
2018-12-17T22:04:59.939392383Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 5)
2018-12-17T22:04:59.948027932Z 66 PC: 136ef | Move file pointer
2018-12-17T22:04:59.950058165Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 5)
2018-12-17T22:04:59.958355189Z 66 PC: 136ef | Move file pointer
2018-12-17T22:04:59.960056744Z 64 PC: 135ee | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:04:59.9695986Z 62 PC: 1360d | Close file
2018-12-17T22:04:59.978289343Z 75 PC: 12b9f | Execute program
2018-12-17T22:04:59.988144555Z 71 PC: 12bbb | Get current directory
2018-12-17T22:04:59.991783412Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.002400964Z 61 PC: 135bd | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:05:00.009553319Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 5)
2018-12-17T22:05:00.012747849Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.014316381Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 5)
2018-12-17T22:05:00.02293913Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.025690467Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 5)
2018-12-17T22:05:00.034499861Z 62 PC: 1360d | Close file
2018-12-17T22:05:00.043970589Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.052552691Z 26 PC: 12fd7 | Set disk transfer address
2018-12-17T22:05:00.06970092Z 78 PC: 12fe3 | Find first file
2018-12-17T22:05:00.083832808Z 26 PC: 12fd7 | Set disk transfer address
2018-12-17T22:05:00.086451495Z 78 PC: 12fe3 | Find first file
2018-12-17T22:05:00.091399584Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:05:00.097027127Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.108476997Z 61 PC: 135bd | Open file (Filename = '\TEST.EXE')
2018-12-17T22:05:00.115208014Z 26 PC: 12ffb | Set disk transfer address
2018-12-17T22:05:00.116417919Z 79 PC: 13000 | Find next file
2018-12-17T22:05:00.120134541Z 26 PC: 12fd7 | Set disk transfer address
2018-12-17T22:05:00.121607Z 78 PC: 12fe3 | Find first file
2018-12-17T22:05:00.131140526Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:05:00.138227935Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.477700526Z 61 PC: 135bd | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:05:00.484654575Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 6)
2018-12-17T22:05:00.49183449Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.494279452Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.50697178Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.509653294Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.517643049Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.528393343Z 62 PC: 1360d | Close file
2018-12-17T22:05:00.535554406Z 26 PC: 12ffb | Set disk transfer address
2018-12-17T22:05:00.537783645Z 79 PC: 13000 | Find next file
2018-12-17T22:05:00.541577875Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:05:00.547843293Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.559267404Z 61 PC: 135bd | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T22:05:00.566245829Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 6)
2018-12-17T22:05:00.573588282Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.575771932Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.585048713Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.586504231Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.594224703Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.604967876Z 62 PC: 1360d | Close file
2018-12-17T22:05:00.611783403Z 26 PC: 12ffb | Set disk transfer address
2018-12-17T22:05:00.614352428Z 79 PC: 13000 | Find next file
2018-12-17T22:05:00.618264306Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:05:00.625326802Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.636340031Z 61 PC: 135bd | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T22:05:00.643386038Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 6)
2018-12-17T22:05:00.650915041Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.653675483Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.665652737Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.667346874Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.674919133Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.682507286Z 62 PC: 1360d | Close file
2018-12-17T22:05:00.687226113Z 26 PC: 12ffb | Set disk transfer address
2018-12-17T22:05:00.689207784Z 79 PC: 13000 | Find next file
2018-12-17T22:05:00.692407195Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:05:00.698457084Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.709848629Z 61 PC: 135bd | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T22:05:00.716169529Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 6)
2018-12-17T22:05:00.722284249Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.72405276Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.730835511Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.732290964Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.73803392Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.746602055Z 62 PC: 1360d | Close file
2018-12-17T22:05:00.752610999Z 26 PC: 12ffb | Set disk transfer address
2018-12-17T22:05:00.754133502Z 79 PC: 13000 | Find next file
2018-12-17T22:05:00.757407141Z 67 PC: 12f7f | Get or set file attributes
2018-12-17T22:05:00.761856143Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.768932019Z 61 PC: 135bd | Open file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T22:05:00.774421343Z 63 PC: 13690 | Read file or device (Read 3792 bytes on handle 6)
2018-12-17T22:05:00.780277551Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.782051193Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.788126455Z 66 PC: 136ef | Move file pointer
2018-12-17T22:05:00.790020056Z 64 PC: 13690 | Write file or device (Write 3792 bytes on handle 6)
2018-12-17T22:05:00.798015175Z 67 PC: 12fa6 | Get or set file attributes
2018-12-17T22:05:00.80572221Z 62 PC: 1360d | Close file
2018-12-17T22:05:00.81030637Z 64 PC: 13518 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:05:00.812182989Z 37 PC: 13251 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:00.813332146Z 37 PC: 13251 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:05:00.815215022Z 37 PC: 13251 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:05:00.817169224Z 37 PC: 13251 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:05:00.818529317Z 37 PC: 13251 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:00.819956336Z 37 PC: 13251 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:00.821539738Z 37 PC: 13251 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:05:00.8243775Z 37 PC: 13251 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:05:00.825771926Z 37 PC: 13251 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:05:00.827187336Z 37 PC: 13251 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:05:00.829487092Z 37 PC: 13251 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:05:00.830846365Z 37 PC: 13251 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:05:00.832247632Z 37 PC: 13251 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:05:00.834608653Z 37 PC: 13251 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:05:00.836041697Z 37 PC: 13251 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:05:00.837709577Z 37 PC: 13251 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:05:00.84054541Z 37 PC: 13251 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:05:00.841978884Z 37 PC: 13251 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:05:00.843364487Z 37 PC: 13251 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:05:00.845560007Z 76 PC: 13290 | Terminate with return code (Return code = '0')