Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Scorp.7285

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:36.6389818Z 53 PC: 1418a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.641247224Z 53 PC: 1418a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.643084083Z 53 PC: 1418a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.64469007Z 53 PC: 1418a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.64703343Z 53 PC: 1418a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.648227615Z 53 PC: 1418a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.649555066Z 53 PC: 1418a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.651943495Z 53 PC: 1418a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.653293866Z 53 PC: 1418a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.654879532Z 53 PC: 1418a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.657278526Z 53 PC: 1418a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.658422874Z 53 PC: 1418a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.659626904Z 53 PC: 1418a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.661387642Z 53 PC: 1418a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.663041896Z 53 PC: 1418a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.664574361Z 53 PC: 1418a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:36.666828218Z 53 PC: 1418a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:36.668213775Z 53 PC: 1418a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.669679711Z 53 PC: 1418a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:36.671525942Z 37 PC: 1419f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.673689559Z 37 PC: 141a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.675265625Z 37 PC: 141af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.677055374Z 37 PC: 141b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.67839579Z 68 PC: 14e63 | I/O control for devices (Set for = '')
2018-12-17T23:11:36.739465957Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.741715264Z 60 PC: 148e1 | Create or truncate file
2018-12-17T23:11:36.758399909Z 65 PC: 14a2a | Delete file (Filename = '\�')
2018-12-17T23:11:36.768904616Z 53 PC: 13fcf | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.770802828Z 37 PC: 13feb | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.772125261Z 51 PC: 13ecf | Get or set Ctrl-Break
2018-12-17T23:11:36.773008045Z 48 PC: 14aa3 | Get DOS version
2018-12-17T23:11:36.775630021Z 61 PC: 148e1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:36.782269712Z 63 PC: 149b4 | Read file or device (Read 7285 bytes on handle 6)
2018-12-17T23:11:36.789990162Z 62 PC: 14931 | Close file
2018-12-17T23:11:36.792477177Z 26 PC: 13f6e | Set disk transfer address
2018-12-17T23:11:36.79400363Z 78 PC: 13f7a | Find first file
2018-12-17T23:11:36.801097364Z 61 PC: 148e1 | Open file (Filename = '\TEST.EXE')
2018-12-17T23:11:36.805746115Z 66 PC: 14a13 | Move file pointer
2018-12-17T23:11:36.80735693Z 63 PC: 149b4 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T23:11:36.81028272Z 62 PC: 14931 | Close file
2018-12-17T23:11:36.812543158Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.813546351Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.816164897Z 26 PC: 13f6e | Set disk transfer address
2018-12-17T23:11:36.818350292Z 78 PC: 13f7a | Find first file
2018-12-17T23:11:36.823966345Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.824963926Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.827913954Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.829245182Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.831942064Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.833580956Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.836384525Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.837598479Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.84069587Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.842049298Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.844748468Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.847661281Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.857955282Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.858972268Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.861566695Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.862793703Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.865762577Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.866712766Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.868784673Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.86961695Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.871568363Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.87269274Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.874503056Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.875536337Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.877784347Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.878714472Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.881136746Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.882054627Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.883918585Z 26 PC: 13f92 | Set disk transfer address
2018-12-17T23:11:36.88506262Z 79 PC: 13f97 | Find next file
2018-12-17T23:11:36.887274508Z 44 PC: 13e7d | Get time 0x13e7d: xor ah, ah
0x13e7f: mov al, dl
0x13e81: les di, ptr [bp + 6]
0x13e84: stosw word ptr es:[di], ax
0x13e85: mov al, dh
0x13e87: les di, ptr [bp + 0xa]
0x13e8a: stosw word ptr es:[di], ax
0x13e8b: mov al, cl
0x13e8d: les di, ptr [bp + 0xe]
0x13e90: stosw word ptr es:[di], ax
0x13e91: mov al, ch
0x13e93: les di, ptr [bp + 0x12]
0x13e96: stosw word ptr es:[di], ax
0x13e97: pop bp
0x13e98: retf 0x10
0x13e9b: push bp
0x13e9c: mov bp, sp
0x13e9e: mov ch, byte ptr [bp + 0xc]
0x13ea1: mov cl, byte ptr [bp + 0xa]
0x13ea4: mov dh, byte ptr [bp + 8]
2018-12-17T23:11:36.888898568Z 48 PC: 14aa3 | Get DOS version
2018-12-17T23:11:36.890166329Z 26 PC: 13f6e | Set disk transfer address
2018-12-17T23:11:36.891452959Z 78 PC: 13f7a | Find first file
2018-12-17T23:11:36.895200652Z 48 PC: 14aa3 | Get DOS version
2018-12-17T23:11:36.896640322Z 61 PC: 148e1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:36.903425306Z 66 PC: 14a13 | Move file pointer
2018-12-17T23:11:36.904762482Z 63 PC: 149b4 | Read file or device (Read 7285 bytes on handle 6)
2018-12-17T23:11:36.912342352Z 66 PC: 14a13 | Move file pointer
2018-12-17T23:11:36.913908401Z 64 PC: 14912 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:11:36.921782644Z 66 PC: 14a13 | Move file pointer
2018-12-17T23:11:36.923160469Z 64 PC: 149b4 | Write file or device (Write 7285 bytes on handle 6)
2018-12-17T23:11:36.931741466Z 62 PC: 14931 | Close file
2018-12-17T23:11:36.939936605Z 37 PC: 13feb | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.941021692Z 53 PC: 14108 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.942499442Z 37 PC: 14111 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:36.943776763Z 53 PC: 14108 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.945091553Z 37 PC: 14111 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:36.946781816Z 53 PC: 14108 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.948571888Z 37 PC: 14111 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:36.949866933Z 53 PC: 14108 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.952024739Z 37 PC: 14111 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:36.953320512Z 53 PC: 14108 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.954321798Z 37 PC: 14111 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:36.957112995Z 53 PC: 14108 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.958575864Z 37 PC: 14111 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:36.959549188Z 53 PC: 14108 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.96232952Z 37 PC: 14111 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:36.963237002Z 53 PC: 14108 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.964234338Z 37 PC: 14111 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:36.966304761Z 53 PC: 14108 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.967261598Z 37 PC: 14111 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:36.968278872Z 53 PC: 14108 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.969691401Z 37 PC: 14111 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:36.970902652Z 53 PC: 14108 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.971874216Z 37 PC: 14111 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:36.973818406Z 53 PC: 14108 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.974889547Z 37 PC: 14111 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:36.975982285Z 53 PC: 14108 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.977153093Z 37 PC: 14111 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:36.978066319Z 53 PC: 14108 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.979386831Z 37 PC: 14111 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:36.980778311Z 53 PC: 14108 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.981790423Z 37 PC: 14111 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:36.982900044Z 53 PC: 14108 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:36.984184402Z 37 PC: 14111 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:36.98509732Z 53 PC: 14108 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:36.98641935Z 37 PC: 14111 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:36.987619302Z 53 PC: 14108 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.988580059Z 37 PC: 14111 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:36.989757683Z 53 PC: 14108 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:36.998018852Z 37 PC: 14111 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:36.999795445Z 41 PC: 140bf | Parse filename
2018-12-17T23:11:37.00149553Z 41 PC: 140cd | Parse filename
2018-12-17T23:11:37.01757272Z 75 PC: 140d8 | Execute program
2018-12-17T23:11:37.040352069Z 80 PC: 1c559 | Set current PSP
2018-12-17T23:11:37.050549527Z 48 PC: 1c55e | Get DOS version
2018-12-17T23:11:37.052548539Z 99 PC: 22d40 | Get DBCS lead byte table pointer
2018-12-17T23:11:37.05534829Z 101 PC: 1c5e4 | Get extended country info
2018-12-17T23:11:37.057924865Z 99 PC: 1c5ea | Get DBCS lead byte table pointer
2018-12-17T23:11:37.065656131Z 74 PC: 1c64c | Reallocate memory
2018-12-17T23:11:37.066792707Z 25 PC: 1c683 | Get default drive
2018-12-17T23:11:37.073616573Z 37 PC: 1c143 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:11:37.074716315Z 37 PC: 1c14a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:37.07563534Z 37 PC: 1c151 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:37.078957299Z 74 PC: 1b2ec | Reallocate memory
2018-12-17T23:11:37.080014833Z 72 PC: 1b32d | Allocate memory
2018-12-17T23:11:37.081083678Z 72 PC: 1b365 | Allocate memory
2018-12-17T23:11:37.082904104Z 72 PC: 1b36d | Allocate memory