Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Lipstick.4784

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:37.95111754Z 53 PC: 130aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:37.95312885Z 53 PC: 130aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:37.954321174Z 53 PC: 130aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:37.95543188Z 53 PC: 130aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:37.956527304Z 53 PC: 130aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:37.959503395Z 53 PC: 130aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:37.961363047Z 53 PC: 130aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:37.96279228Z 53 PC: 130aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:37.965217375Z 53 PC: 130aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:37.966464282Z 53 PC: 130aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:37.967694262Z 53 PC: 130aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:37.969944615Z 53 PC: 130aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:37.971220556Z 53 PC: 130aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:37.972392401Z 53 PC: 130aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:37.974729817Z 53 PC: 130aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:37.976570413Z 53 PC: 130aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:37.978005035Z 53 PC: 130aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:37.979425811Z 53 PC: 130aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:37.981772473Z 53 PC: 130aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:37.982912021Z 37 PC: 130bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:37.983988792Z 37 PC: 130c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:37.996332139Z 37 PC: 130cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:37.997513793Z 37 PC: 130d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:37.999036868Z 68 PC: 13dc3 | I/O control for devices (Set for = '')
2018-12-17T23:10:38.00184151Z 48 PC: 138f3 | Get DOS version
2018-12-17T23:10:38.003593535Z 25 PC: 13980 | Get default drive
2018-12-17T23:10:38.004995139Z 71 PC: 13993 | Get current directory
2018-12-17T23:10:38.013143732Z 44 PC: 13efa | Get time 0x13efa: mov word ptr [0x3e], cx
0x13efe: mov word ptr [0x40], dx
0x13f02: retf
0x13f03: mov cx, di
0x13f05: mov si, 0xa
0x13f08: mov bx, dx
0x13f0a: or bx, bx
0x13f0c: jns 0x13f1f
0x13f0e: neg bx
0x13f10: neg ax
0x13f12: sbb bx, 0
0x13f15: call 0x13f1f
0x13f18: dec di
0x13f19: mov byte ptr es:[di], 0x2d
0x13f1d: inc cx
0x13f1e: ret
0x13f1f: xor dx, dx
0x13f21: xchg ax, bx
0x13f22: div si
0x13f24: xchg ax, bx
2018-12-17T23:10:38.015683933Z 26 PC: 12f27 | Set disk transfer address
2018-12-17T23:10:38.01709319Z 78 PC: 12f33 | Find first file
2018-12-17T23:10:38.0294144Z 26 PC: 12f27 | Set disk transfer address
2018-12-17T23:10:38.030600756Z 78 PC: 12f33 | Find first file
2018-12-17T23:10:38.036799475Z 61 PC: 137a5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:38.045138897Z 66 PC: 138d7 | Move file pointer
2018-12-17T23:10:38.047693346Z 63 PC: 13878 | Read file or device (Read 4784 bytes on handle 5)
2018-12-17T23:10:38.055284802Z 62 PC: 137f5 | Close file
2018-12-17T23:10:38.058523484Z 67 PC: 12ecf | Get or set file attributes
2018-12-17T23:10:38.0654866Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T23:10:38.081925168Z 61 PC: 137a5 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:10:38.090640609Z 66 PC: 138d7 | Move file pointer
2018-12-17T23:10:38.092612156Z 63 PC: 13878 | Read file or device (Read 4784 bytes on handle 5)
2018-12-17T23:10:38.100502949Z 62 PC: 137f5 | Close file
2018-12-17T23:10:38.103441242Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T23:10:38.114212256Z 26 PC: 12f4b | Set disk transfer address
2018-12-17T23:10:38.115703217Z 79 PC: 12f50 | Find next file
2018-12-17T23:10:38.118793598Z 26 PC: 12f4b | Set disk transfer address
2018-12-17T23:10:38.120535194Z 79 PC: 12f50 | Find next file
2018-12-17T23:10:38.123743802Z 67 PC: 12ecf | Get or set file attributes
2018-12-17T23:10:38.13103967Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T23:10:38.141114355Z 61 PC: 137a5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:38.148131358Z 66 PC: 14047 | Move file pointer
2018-12-17T23:10:38.150002862Z 66 PC: 14055 | Move file pointer
2018-12-17T23:10:38.152179878Z 66 PC: 14063 | Move file pointer
2018-12-17T23:10:38.154074496Z 66 PC: 138d7 | Move file pointer
2018-12-17T23:10:38.155766372Z 63 PC: 13878 | Read file or device (Read 4784 bytes on handle 5)
2018-12-17T23:10:38.164798387Z 66 PC: 138d7 | Move file pointer
2018-12-17T23:10:38.166453003Z 63 PC: 13878 | Read file or device (Read 4784 bytes on handle 5)
2018-12-17T23:10:38.173941597Z 66 PC: 138d7 | Move file pointer
2018-12-17T23:10:38.176352187Z 64 PC: 13878 | Write file or device (Write 4784 bytes on handle 5)
2018-12-17T23:10:38.184712392Z 62 PC: 137f5 | Close file
2018-12-17T23:10:38.192534273Z 53 PC: 13028 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:38.194872359Z 37 PC: 13031 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:38.196197999Z 53 PC: 13028 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:38.197568989Z 37 PC: 13031 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:38.199850953Z 53 PC: 13028 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:38.201213985Z 37 PC: 13031 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:38.202575966Z 53 PC: 13028 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:38.2047464Z 37 PC: 13031 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:38.206250144Z 53 PC: 13028 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:38.207588438Z 37 PC: 13031 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:38.20949934Z 53 PC: 13028 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:38.21087175Z 37 PC: 13031 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:38.212175997Z 53 PC: 13028 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:38.214259335Z 37 PC: 13031 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:38.21584713Z 53 PC: 13028 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:38.217174228Z 37 PC: 13031 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:38.219170223Z 53 PC: 13028 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:38.220788476Z 37 PC: 13031 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:38.222097202Z 53 PC: 13028 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:38.224114108Z 37 PC: 13031 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:38.225956789Z 53 PC: 13028 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:38.227041775Z 37 PC: 13031 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:38.22828145Z 53 PC: 13028 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:38.229858901Z 37 PC: 13031 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:38.230961625Z 53 PC: 13028 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:38.232033487Z 37 PC: 13031 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:38.233686636Z 53 PC: 13028 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:38.234835485Z 37 PC: 13031 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:38.235885038Z 53 PC: 13028 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:38.237932093Z 37 PC: 13031 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:38.238981328Z 53 PC: 13028 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:38.240055189Z 37 PC: 13031 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:38.242169488Z 53 PC: 13028 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:38.243357245Z 37 PC: 13031 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:38.244422466Z 53 PC: 13028 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:38.246918003Z 37 PC: 13031 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:38.248215259Z 53 PC: 13028 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:38.251051071Z 37 PC: 13031 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:38.253670205Z 41 PC: 12fdf | Parse filename
2018-12-17T23:10:38.25533366Z 41 PC: 12fed | Parse filename
2018-12-17T23:10:38.256977917Z 75 PC: 12ff8 | Execute program
2018-12-17T23:10:38.272745505Z 53 PC: 13028 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:38.274461816Z 37 PC: 13031 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:38.275827853Z 53 PC: 13028 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:38.277910064Z 37 PC: 13031 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:38.279592783Z 53 PC: 13028 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:38.280983039Z 37 PC: 13031 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:38.2825265Z 53 PC: 13028 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:38.284688932Z 37 PC: 13031 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:38.286054972Z 53 PC: 13028 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:38.28743512Z 37 PC: 13031 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:38.289735223Z 53 PC: 13028 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:38.291133278Z 37 PC: 13031 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:38.293006779Z 53 PC: 13028 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:38.2953257Z 37 PC: 13031 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:38.296441598Z 53 PC: 13028 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:38.297555869Z 37 PC: 13031 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:38.299926561Z 53 PC: 13028 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:38.301457403Z 37 PC: 13031 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:38.302526491Z 53 PC: 13028 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:38.304505373Z 37 PC: 13031 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:38.305580624Z 53 PC: 13028 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:38.306666122Z 37 PC: 13031 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:38.308462035Z 53 PC: 13028 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:38.309576089Z 37 PC: 13031 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:38.310643111Z 53 PC: 13028 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:38.31244187Z 37 PC: 13031 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:38.313801594Z 53 PC: 13028 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:38.314954634Z 37 PC: 13031 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:38.317265394Z 53 PC: 13028 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:38.319394559Z 37 PC: 13031 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:38.320765457Z 53 PC: 13028 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:38.323091084Z 37 PC: 13031 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:38.324469561Z 53 PC: 13028 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:38.325857597Z 37 PC: 13031 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:38.327886672Z 53 PC: 13028 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:38.329535771Z 37 PC: 13031 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:38.330835304Z 53 PC: 13028 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:38.332364372Z 37 PC: 13031 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:38.334714413Z 61 PC: 137a5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:38.341549297Z 66 PC: 138d7 | Move file pointer
2018-12-17T23:10:38.342918417Z 64 PC: 13878 | Write file or device (Write 4784 bytes on handle 5)
2018-12-17T23:10:38.35193885Z 62 PC: 137f5 | Close file
2018-12-17T23:10:38.359981928Z 67 PC: 12ef6 | Get or set file attributes
2018-12-17T23:10:38.369650753Z 14 PC: 139d9 | Set default drive (Drive = 'A')
2018-12-17T23:10:38.371910831Z 25 PC: 139dd | Get default drive
2018-12-17T23:10:38.373264996Z 59 PC: 13a47 | Change current directory
2018-12-17T23:10:38.378231394Z 64 PC: 1346d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:10:38.381227689Z 37 PC: 13201 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:38.3827028Z 37 PC: 13201 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:38.384103603Z 37 PC: 13201 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:38.386344352Z 37 PC: 13201 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:38.38806736Z 37 PC: 13201 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:38.389470916Z 37 PC: 13201 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:38.39163373Z 37 PC: 13201 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:38.393350725Z 37 PC: 13201 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:38.394732383Z 37 PC: 13201 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:38.396871229Z 37 PC: 13201 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:38.398586658Z 37 PC: 13201 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:38.399971034Z 37 PC: 13201 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:38.402081456Z 37 PC: 13201 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:38.40376098Z 37 PC: 13201 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:38.405160004Z 37 PC: 13201 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:38.406749775Z 37 PC: 13201 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:38.408943067Z 37 PC: 13201 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:38.410336272Z 37 PC: 13201 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:38.411728954Z 37 PC: 13201 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:38.414097951Z 76 PC: 13240 | Terminate with return code (Return code = '0')