Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5047

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:36.248730462Z 53 PC: 1356a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.251622833Z 53 PC: 1356a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.254439176Z 53 PC: 1356a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.256424771Z 53 PC: 1356a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.259511861Z 53 PC: 1356a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.271060122Z 53 PC: 1356a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.273053833Z 53 PC: 1356a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.276661047Z 53 PC: 1356a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.278503699Z 53 PC: 1356a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.280241343Z 53 PC: 1356a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.282855042Z 53 PC: 1356a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.284770135Z 53 PC: 1356a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.286635104Z 53 PC: 1356a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.289699189Z 53 PC: 1356a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.291689172Z 53 PC: 1356a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.293505081Z 53 PC: 1356a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:36.295390738Z 53 PC: 1356a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:36.298044259Z 53 PC: 1356a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.299337147Z 53 PC: 1356a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:36.300596692Z 37 PC: 1357f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.303402668Z 37 PC: 13587 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.305445519Z 37 PC: 1358f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.30757001Z 37 PC: 13597 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.314482004Z 68 PC: 142c2 | I/O control for devices (Set for = '')
2018-12-17T23:11:36.327983599Z 60 PC: 13c30 | Create or truncate file
2018-12-17T23:11:36.347346821Z 65 PC: 13d79 | Delete file (Filename = '_._')
2018-12-17T23:11:36.37794734Z 26 PC: 13377 | Set disk transfer address
2018-12-17T23:11:36.37938934Z 78 PC: 13383 | Find first file
2018-12-17T23:11:36.386527348Z 48 PC: 13df2 | Get DOS version
2018-12-17T23:11:36.389395834Z 67 PC: 1331f | Get or set file attributes
2018-12-17T23:11:36.396717601Z 67 PC: 13346 | Get or set file attributes
2018-12-17T23:11:36.683818745Z 61 PC: 13c30 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:36.692448184Z 63 PC: 13d03 | Read file or device (Read 5046 bytes on handle 6)
2018-12-17T23:11:36.702268214Z 66 PC: 143c1 | Move file pointer
2018-12-17T23:11:36.70425004Z 66 PC: 143cf | Move file pointer
2018-12-17T23:11:36.706464108Z 66 PC: 143dd | Move file pointer
2018-12-17T23:11:36.709428269Z 66 PC: 13d62 | Move file pointer
2018-12-17T23:11:36.711449712Z 63 PC: 13d03 | Read file or device (Read 5047 bytes on handle 6)
2018-12-17T23:11:36.721001738Z 62 PC: 13c80 | Close file
2018-12-17T23:11:36.724557152Z 61 PC: 13c30 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:36.732368623Z 64 PC: 13d03 | Write file or device (Write 5046 bytes on handle 6)
2018-12-17T23:11:36.741606874Z 66 PC: 143c1 | Move file pointer
2018-12-17T23:11:36.744434074Z 66 PC: 143cf | Move file pointer
2018-12-17T23:11:36.746491432Z 66 PC: 143dd | Move file pointer
2018-12-17T23:11:36.748793891Z 66 PC: 13d62 | Move file pointer
2018-12-17T23:11:36.751490845Z 64 PC: 13c61 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:11:36.760799234Z 62 PC: 13c80 | Close file
2018-12-17T23:11:36.769649267Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.771679403Z 37 PC: 134ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.774355574Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.776099389Z 37 PC: 134ef | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.777848132Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.780661075Z 37 PC: 134ef | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.782368112Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.784062992Z 37 PC: 134ef | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.78704303Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.78931605Z 37 PC: 134ef | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.792053182Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.794025072Z 37 PC: 134ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.79544358Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.797240415Z 37 PC: 134ef | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.799266018Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.801261046Z 37 PC: 134ef | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.802641535Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.804791286Z 37 PC: 134ef | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.806110348Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.807498499Z 37 PC: 134ef | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.809772533Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.8111685Z 37 PC: 134ef | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.812454475Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.814000117Z 37 PC: 134ef | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.816160399Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.817584956Z 37 PC: 134ef | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.819093316Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.823302128Z 37 PC: 134ef | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.827113167Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.828570441Z 37 PC: 134ef | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.831310001Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:36.833097315Z 37 PC: 134ef | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:36.835621096Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:36.837378604Z 37 PC: 134ef | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:36.839438934Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.841136865Z 37 PC: 134ef | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.842960788Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:36.844977646Z 37 PC: 134ef | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:36.846835489Z 48 PC: 13df2 | Get DOS version
2018-12-17T23:11:36.849230334Z 41 PC: 1349d | Parse filename
2018-12-17T23:11:36.852273543Z 41 PC: 134ab | Parse filename
2018-12-17T23:11:36.854284201Z 75 PC: 134b6 | Execute program
2018-12-17T23:11:36.875828104Z 48 PC: 272f3 | Get DOS version
2018-12-17T23:11:36.879669822Z 53 PC: 285a2 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:11:36.882265851Z 74 PC: 26ed8 | Reallocate memory
2018-12-17T23:11:36.884650811Z 74 PC: 26edc | Reallocate memory
2018-12-17T23:11:36.889774746Z 37 PC: 2a1e0 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:11:36.914904587Z 37 PC: 2a12e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:11:36.919015754Z 76 PC: 26d7c | Terminate with return code (Return code = '0')
2018-12-17T23:11:36.923931602Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.925887427Z 37 PC: 134ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.928071476Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.931387076Z 37 PC: 134ef | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.933217263Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.935053207Z 37 PC: 134ef | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.93769595Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.939583577Z 37 PC: 134ef | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.941217721Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.943922844Z 37 PC: 134ef | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.945995483Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.947684491Z 37 PC: 134ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.950177078Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.952295875Z 37 PC: 134ef | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.953931488Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.956409469Z 37 PC: 134ef | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.958342017Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.960020673Z 37 PC: 134ef | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.96236971Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.964334085Z 37 PC: 134ef | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.969949487Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.971578261Z 37 PC: 134ef | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.973849416Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.975172845Z 37 PC: 134ef | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.976570593Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.978912838Z 37 PC: 134ef | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.980690035Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.982188119Z 37 PC: 134ef | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.984618246Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.986060243Z 37 PC: 134ef | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.987387139Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:37.007940287Z 37 PC: 134ef | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:37.011967451Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:37.013842692Z 37 PC: 134ef | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:37.016959249Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:37.018874336Z 37 PC: 134ef | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:37.020729543Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:37.023974181Z 37 PC: 134ef | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:37.025556744Z 61 PC: 13c30 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:37.039780694Z 64 PC: 13d03 | Write file or device (Write 5046 bytes on handle 6)
2018-12-17T23:11:37.054106356Z 66 PC: 143c1 | Move file pointer
2018-12-17T23:11:37.056291647Z 66 PC: 143cf | Move file pointer
2018-12-17T23:11:37.058528498Z 66 PC: 143dd | Move file pointer
2018-12-17T23:11:37.06206993Z 66 PC: 13d62 | Move file pointer
2018-12-17T23:11:37.065341231Z 64 PC: 13d03 | Write file or device (Write 5047 bytes on handle 6)
2018-12-17T23:11:37.076123955Z 62 PC: 13c80 | Close file
2018-12-17T23:11:37.087446987Z 67 PC: 13346 | Get or set file attributes
2018-12-17T23:11:37.099297277Z 25 PC: 13e7f | Get default drive
2018-12-17T23:11:37.100979011Z 71 PC: 13e92 | Get current directory
2018-12-17T23:11:37.105647795Z 26 PC: 13377 | Set disk transfer address
2018-12-17T23:11:37.107679373Z 78 PC: 13383 | Find first file
2018-12-17T23:11:37.115131528Z 67 PC: 1331f | Get or set file attributes
2018-12-17T23:11:37.122148806Z 67 PC: 13346 | Get or set file attributes
2018-12-17T23:11:37.137158599Z 61 PC: 13c30 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:11:37.151072551Z 66 PC: 13d62 | Move file pointer
2018-12-17T23:11:37.153180556Z 63 PC: 13d03 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T23:11:37.162566119Z 62 PC: 13c80 | Close file
2018-12-17T23:11:37.165026306Z 67 PC: 13346 | Get or set file attributes
2018-12-17T23:11:37.17662025Z 26 PC: 1339b | Set disk transfer address
2018-12-17T23:11:37.179477663Z 79 PC: 133a0 | Find next file
2018-12-17T23:11:37.188621279Z 14 PC: 13ed8 | Set default drive (Drive = 'C')
2018-12-17T23:11:37.190502025Z 25 PC: 13edc | Get default drive
2018-12-17T23:11:37.193329927Z 59 PC: 13f46 | Change current directory
2018-12-17T23:11:37.199848804Z 26 PC: 13377 | Set disk transfer address
2018-12-17T23:11:37.20154435Z 78 PC: 13383 | Find first file
2018-12-17T23:11:37.209429873Z 14 PC: 13ed8 | Set default drive (Drive = 'A')
2018-12-17T23:11:37.211691029Z 25 PC: 13edc | Get default drive
2018-12-17T23:11:37.213410174Z 59 PC: 13f46 | Change current directory
2018-12-17T23:11:37.220196493Z 64 PC: 13988 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:11:37.22295212Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:37.224690966Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:37.227286991Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:37.22939069Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:37.231129137Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:37.233645869Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:37.235703604Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:37.237390851Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:37.23930999Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:37.241899267Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:37.243592843Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:37.245303885Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:37.247546422Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:37.249138996Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:37.250731705Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:37.253343628Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:37.25494054Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:37.256535404Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:37.259459918Z 37 PC: 136c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:37.261094042Z 76 PC: 13700 | Terminate with return code (Return code = '0')