Sample viewer

vx.netlux.org/Virus.DOS.HLLW.RanDir.5584

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:40.678634004Z 53 PC: 130ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:40.680776402Z 53 PC: 130ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:40.682214636Z 53 PC: 130ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:40.683718899Z 53 PC: 130ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:40.685530616Z 53 PC: 130ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:40.687363144Z 53 PC: 130ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:40.689536702Z 53 PC: 130ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:40.691672246Z 53 PC: 130ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:40.693542044Z 53 PC: 130ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:40.695263101Z 53 PC: 130ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:40.697104607Z 53 PC: 130ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:40.699076076Z 53 PC: 130ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:40.700445493Z 53 PC: 130ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:40.70183229Z 53 PC: 130ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:40.707727825Z 53 PC: 130ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:40.709099988Z 53 PC: 130ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:40.710573446Z 53 PC: 130ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:40.713407953Z 53 PC: 130ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:40.726556963Z 53 PC: 130ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:40.727953637Z 37 PC: 130df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:40.732720415Z 37 PC: 130e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:40.734038417Z 37 PC: 130ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:40.735239715Z 37 PC: 130f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:40.739150828Z 68 PC: 139fe | I/O control for devices (Set for = '�II �x ����ø`��w���@')
2018-12-17T23:11:40.741149603Z 48 PC: 13724 | Get DOS version
2018-12-17T23:11:40.744699642Z 26 PC: 12e45 | Set disk transfer address
2018-12-17T23:11:40.746439992Z 78 PC: 12e51 | Find first file
2018-12-17T23:11:40.753079266Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.754441162Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.757715996Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.762005718Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.765622253Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.767379278Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.772387552Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.773765653Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.776667735Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.794603236Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.797936394Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.800006762Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.804853713Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.80605694Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.80928172Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.811847496Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.815123894Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.817154987Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.821775056Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.823913127Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.827468306Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.829435299Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.833201417Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.835215179Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.838484452Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.841266196Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.844633697Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.846311646Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.850879072Z 26 PC: 12e69 | Set disk transfer address
2018-12-17T23:11:40.852555381Z 79 PC: 12e6e | Find next file
2018-12-17T23:11:40.855617011Z 44 PC: 13e96 | Get time 0x13e96: mov word ptr [0x3e], cx
0x13e9a: mov word ptr [0x40], dx
0x13e9e: retf
0x13e9f: mov di, 0x50
0x13ea2: push ds
0x13ea3: pop es
0x13ea4: mov cx, 0x3b0
0x13ea7: sub cx, di
0x13ea9: shr cx, 1
0x13eab: xor ax, ax
0x13ead: cld
0x13eae: rep stosd dword ptr es:[di], eax
0x13eb0: ret
0x13eb1: add byte ptr [bx + si], al
0x13eb3: add byte ptr [bx + si], al
0x13eb5: add byte ptr [bx + si], al
0x13eb7: add byte ptr [bx + si], al
0x13eb9: add byte ptr [bx + si], al
0x13ebb: add byte ptr [bx + si], al
0x13ebd: add byte ptr [bx + si], al
2018-12-17T23:11:40.861465746Z 48 PC: 13724 | Get DOS version
2018-12-17T23:11:40.863687472Z 41 PC: 13034 | Parse filename
2018-12-17T23:11:40.865779851Z 41 PC: 13042 | Parse filename
2018-12-17T23:11:40.868704Z 75 PC: 1304d | Execute program
2018-12-17T23:11:40.894195591Z 80 PC: 180a9 | Set current PSP
2018-12-17T23:11:40.895234625Z 48 PC: 180ae | Get DOS version
2018-12-17T23:11:40.897058623Z 99 PC: 1e890 | Get DBCS lead byte table pointer
2018-12-17T23:11:40.900607015Z 101 PC: 18134 | Get extended country info
2018-12-17T23:11:40.902412315Z 99 PC: 1813a | Get DBCS lead byte table pointer
2018-12-17T23:11:40.904166134Z 74 PC: 1819c | Reallocate memory
2018-12-17T23:11:40.906888859Z 25 PC: 181d3 | Get default drive
2018-12-17T23:11:40.908557869Z 37 PC: 17c93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:11:40.910278402Z 37 PC: 17c9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:40.912494246Z 37 PC: 17ca1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:40.918905478Z 74 PC: 16e3c | Reallocate memory
2018-12-17T23:11:40.920864578Z 72 PC: 16e7d | Allocate memory
2018-12-17T23:11:40.92347266Z 72 PC: 16eb5 | Allocate memory
2018-12-17T23:11:40.925714806Z 72 PC: 16ebd | Allocate memory