Sample viewer

vx.netlux.org/Virus.DOS.HLLW.Arj.5744

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:08.018882577Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:08.020367504Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:08.021641888Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:08.02283163Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:08.024758714Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:08.025785572Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:08.026849387Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:08.028253293Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:08.029217221Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:08.030074341Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:08.031266332Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:08.033394916Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:08.034889176Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:08.03661784Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:08.038512523Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:08.039546384Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:08.04055269Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:08.042736311Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:08.043780768Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:08.044896416Z 37 PC: 12f1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:08.046611504Z 37 PC: 12f27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:08.047680494Z 37 PC: 12f2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:08.048766102Z 37 PC: 12f37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:08.050754178Z 68 PC: 13e1a | I/O control for devices (Set for = '����')
2018-12-17T23:11:08.052627573Z 48 PC: 13a2b | Get DOS version
2018-12-17T23:11:08.054471026Z 61 PC: 13869 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:08.073135288Z 66 PC: 13f19 | Move file pointer
2018-12-17T23:11:08.074502561Z 66 PC: 13f27 | Move file pointer
2018-12-17T23:11:08.075762471Z 66 PC: 13f35 | Move file pointer
2018-12-17T23:11:08.077691097Z 63 PC: 1393c | Read file or device (Read 5744 bytes on handle 5)
2018-12-17T23:11:08.085631306Z 62 PC: 138b9 | Close file
2018-12-17T23:11:08.087425864Z 60 PC: 13869 | Create or truncate file
2018-12-17T23:11:08.104053686Z 64 PC: 1393c | Write file or device (Write 5744 bytes on handle 5)
2018-12-17T23:11:08.110214176Z 62 PC: 138b9 | Close file
2018-12-17T23:11:08.118505346Z 26 PC: 12d15 | Set disk transfer address
2018-12-17T23:11:08.120232968Z 78 PC: 12d21 | Find first file
2018-12-17T23:11:08.129757439Z 26 PC: 12d15 | Set disk transfer address
2018-12-17T23:11:08.131149003Z 78 PC: 12d21 | Find first file
2018-12-17T23:11:08.137844495Z 65 PC: 139b2 | Delete file (Filename = '')
2018-12-17T23:11:08.14932305Z 64 PC: 13530 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:11:08.154293901Z 64 PC: 13530 | Write file or device (Write 31 bytes on handle 1)
2018-12-17T23:11:08.160044532Z 64 PC: 13530 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:11:08.164936823Z 64 PC: 13530 | Write file or device (Write 15 bytes on handle 1)
2018-12-17T23:11:08.169838048Z 64 PC: 13530 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:11:08.173093249Z 37 PC: 13061 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:08.174978264Z 37 PC: 13061 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:08.175988444Z 37 PC: 13061 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:08.177404943Z 37 PC: 13061 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:08.17878351Z 37 PC: 13061 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:08.179784394Z 37 PC: 13061 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:08.181253463Z 37 PC: 13061 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:08.182304179Z 37 PC: 13061 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:08.183318272Z 37 PC: 13061 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:08.18456839Z 37 PC: 13061 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:08.185713666Z 37 PC: 13061 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:08.18664605Z 37 PC: 13061 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:08.188144654Z 37 PC: 13061 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:08.189099358Z 37 PC: 13061 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:08.190060309Z 37 PC: 13061 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:08.191259618Z 37 PC: 13061 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:08.192435082Z 37 PC: 13061 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:08.193421408Z 37 PC: 13061 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:08.195314398Z 37 PC: 13061 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:08.196310879Z 76 PC: 130a0 | Terminate with return code (Return code = '0')