Sample viewer

vx.netlux.org/Virus.DOS.HLLC.MF.5216

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:29.284279797Z 53 PC: 130ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:29.28567121Z 53 PC: 130ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:29.28755573Z 53 PC: 130ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:29.289379935Z 53 PC: 130ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:29.291194683Z 53 PC: 130ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:29.293970865Z 53 PC: 130ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:29.295479356Z 53 PC: 130ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:29.297038872Z 53 PC: 130ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:29.313917446Z 53 PC: 130ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:29.315363943Z 53 PC: 130ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:29.31688125Z 53 PC: 130ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:29.31889672Z 53 PC: 130ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:29.320317026Z 53 PC: 130ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:29.321903492Z 53 PC: 130ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:29.323506359Z 53 PC: 130ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:29.325594783Z 53 PC: 130ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:29.327152389Z 53 PC: 130ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:29.328481309Z 53 PC: 130ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:29.33004011Z 53 PC: 130ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:29.331950337Z 37 PC: 130df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:29.333380997Z 37 PC: 130e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:29.335448717Z 37 PC: 130ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:29.336781715Z 37 PC: 130f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:29.338524666Z 68 PC: 13bb8 | I/O control for devices (Set for = '')
2018-12-17T23:11:29.341226878Z 48 PC: 138de | Get DOS version
2018-12-17T23:11:29.343681247Z 61 PC: 13790 | Open file (Filename = 'A:\TEST.exe')
2018-12-17T23:11:29.352131263Z 62 PC: 137e0 | Close file
2018-12-17T23:11:29.355602693Z 41 PC: 13031 | Parse filename
2018-12-17T23:11:29.357293918Z 41 PC: 1303f | Parse filename
2018-12-17T23:11:29.360849243Z 75 PC: 1304a | Execute program
2018-12-17T23:11:29.386750095Z 80 PC: 19749 | Set current PSP
2018-12-17T23:11:29.388117217Z 48 PC: 1974e | Get DOS version
2018-12-17T23:11:29.390230727Z 99 PC: 1ff30 | Get DBCS lead byte table pointer
2018-12-17T23:11:29.394295543Z 101 PC: 197d4 | Get extended country info
2018-12-17T23:11:29.396448821Z 99 PC: 197da | Get DBCS lead byte table pointer
2018-12-17T23:11:29.398251763Z 74 PC: 1983c | Reallocate memory
2018-12-17T23:11:29.400249771Z 25 PC: 19873 | Get default drive
2018-12-17T23:11:29.402888227Z 37 PC: 19333 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:11:29.404598359Z 37 PC: 1933a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:29.406238437Z 37 PC: 19341 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:29.411935781Z 74 PC: 184dc | Reallocate memory
2018-12-17T23:11:29.415924956Z 72 PC: 1851d | Allocate memory
2018-12-17T23:11:29.417896218Z 72 PC: 18555 | Allocate memory
2018-12-17T23:11:29.421282989Z 72 PC: 1855d | Allocate memory