Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Bunter.4514

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:49.309365273Z 53 PC: 133ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:49.310660976Z 53 PC: 133ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:49.312091213Z 53 PC: 133ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:49.313680206Z 53 PC: 133ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:49.315348016Z 53 PC: 133ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:49.316789461Z 53 PC: 133ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:49.318589028Z 53 PC: 133ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:49.320575698Z 53 PC: 133ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:49.322015946Z 53 PC: 133ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:49.323781529Z 53 PC: 133ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:49.325230581Z 53 PC: 133ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:49.326453847Z 53 PC: 133ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:49.327921048Z 53 PC: 133ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:49.329396733Z 53 PC: 133ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:49.330589861Z 53 PC: 133ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:49.331974937Z 53 PC: 133ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:49.333083132Z 53 PC: 133ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:49.341372177Z 53 PC: 133ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:49.342716651Z 53 PC: 133ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:49.344188812Z 37 PC: 133ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:49.345124574Z 37 PC: 13407 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:49.345948866Z 37 PC: 1340f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:49.347625463Z 37 PC: 13417 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:49.349130594Z 68 PC: 13e5e | I/O control for devices (Set for = '')
2018-12-17T23:10:49.350536957Z 48 PC: 13a6f | Get DOS version
2018-12-17T23:10:49.352523614Z 61 PC: 138ad | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:49.359276995Z 63 PC: 13980 | Read file or device (Read 4514 bytes on handle 5)
2018-12-17T23:10:49.36668967Z 62 PC: 138fd | Close file
2018-12-17T23:10:49.369457663Z 53 PC: 1320e | Get interrupt vector (Interrupt = '214' AKA 'UNKNOWN!')
2018-12-17T23:10:49.370781891Z 53 PC: 1320e | Get interrupt vector (Interrupt = '25' AKA 'Get default drive')
2018-12-17T23:10:49.372071458Z 37 PC: 1322a | Set interrupt vector (Interrupt = '214' AKA 'UNKNOWN!')
2018-12-17T23:10:49.373872888Z 67 PC: 1310f | Get or set file attributes
2018-12-17T23:10:49.380258251Z 87 PC: 13150 | Get or set file date and time
2018-12-17T23:10:49.381999969Z 67 PC: 13136 | Get or set file attributes
2018-12-17T23:10:49.398842801Z 61 PC: 138ad | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:49.40540712Z 66 PC: 13f5d | Move file pointer
2018-12-17T23:10:49.406784156Z 66 PC: 13f6b | Move file pointer
2018-12-17T23:10:49.408631162Z 66 PC: 13f79 | Move file pointer
2018-12-17T23:10:49.410042295Z 66 PC: 139df | Move file pointer
2018-12-17T23:10:49.411438024Z 63 PC: 13980 | Read file or device (Read 4514 bytes on handle 5)
2018-12-17T23:10:49.419126181Z 66 PC: 139df | Move file pointer
2018-12-17T23:10:49.42047131Z 64 PC: 13980 | Write file or device (Write 4514 bytes on handle 5)
2018-12-17T23:10:49.428300557Z 66 PC: 139df | Move file pointer
2018-12-17T23:10:49.429991122Z 64 PC: 138de | Write file or device (Write 0 bytes on handle 5)
2018-12-17T23:10:49.437799684Z 53 PC: 1335b | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:49.439188119Z 37 PC: 13364 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:49.441416529Z 53 PC: 1335b | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:49.442686081Z 37 PC: 13364 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:49.448864265Z 53 PC: 1335b | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:49.450932413Z 37 PC: 13364 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:49.452070403Z 53 PC: 1335b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:49.453169777Z 37 PC: 13364 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:49.454709201Z 53 PC: 1335b | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:49.455800041Z 37 PC: 13364 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:49.456836018Z 53 PC: 1335b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:49.458732386Z 37 PC: 13364 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:49.460027099Z 53 PC: 1335b | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:49.461398534Z 37 PC: 13364 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:49.463481373Z 53 PC: 1335b | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:49.465197047Z 37 PC: 13364 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:49.467295279Z 53 PC: 1335b | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:49.469720204Z 37 PC: 13364 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:49.471436817Z 53 PC: 1335b | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:49.472815493Z 37 PC: 13364 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:49.474994815Z 53 PC: 1335b | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:49.476302895Z 37 PC: 13364 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:49.477594829Z 53 PC: 1335b | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:49.48236149Z 37 PC: 13364 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:49.48343559Z 53 PC: 1335b | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:49.485568195Z 37 PC: 13364 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:49.486890401Z 53 PC: 1335b | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:49.488124898Z 37 PC: 13364 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:49.489949348Z 53 PC: 1335b | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:49.491640871Z 37 PC: 13364 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:49.492762424Z 53 PC: 1335b | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:49.495591193Z 37 PC: 13364 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:49.496807595Z 53 PC: 1335b | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:49.498171991Z 37 PC: 13364 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:49.500416307Z 53 PC: 1335b | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:49.501852283Z 37 PC: 13364 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:49.503251852Z 53 PC: 1335b | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:49.505627958Z 37 PC: 13364 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:49.507177987Z 41 PC: 132aa | Parse filename
2018-12-17T23:10:49.508823852Z 41 PC: 132b8 | Parse filename
2018-12-17T23:10:49.511278578Z 75 PC: 132c3 | Execute program
2018-12-17T23:10:49.528227117Z 9 PC: 1738c | Display string (Could not find end pointer)