Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Fall.8768

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:46.993058755Z 53 PC: 13afa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:47.001742604Z 53 PC: 13afa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:47.003438467Z 53 PC: 13afa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:47.005058609Z 53 PC: 13afa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:47.007288981Z 53 PC: 13afa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:47.009728863Z 53 PC: 13afa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:47.014288896Z 53 PC: 13afa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:47.028125856Z 53 PC: 13afa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:47.029425608Z 53 PC: 13afa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:47.030579035Z 53 PC: 13afa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:47.032219244Z 53 PC: 13afa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:47.033526584Z 53 PC: 13afa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:47.034815077Z 53 PC: 13afa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:47.03704671Z 53 PC: 13afa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:47.038226227Z 53 PC: 13afa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:47.039326416Z 53 PC: 13afa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:47.040411433Z 53 PC: 13afa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:47.042442095Z 53 PC: 13afa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:47.043531574Z 53 PC: 13afa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:47.044631015Z 37 PC: 13b0f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:47.046566802Z 37 PC: 13b17 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:47.047916115Z 37 PC: 13b1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:47.049255916Z 37 PC: 13b27 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:47.051653841Z 68 PC: 14857 | I/O control for devices (Set for = '')
2018-12-17T23:11:47.053379288Z 25 PC: 1440f | Get default drive
2018-12-17T23:11:47.054682072Z 71 PC: 14422 | Get current directory
2018-12-17T23:11:47.058729996Z 48 PC: 14382 | Get DOS version
2018-12-17T23:11:47.060435271Z 61 PC: 141c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:47.067892053Z 66 PC: 14956 | Move file pointer
2018-12-17T23:11:47.070138697Z 66 PC: 14964 | Move file pointer
2018-12-17T23:11:47.071784321Z 66 PC: 14972 | Move file pointer
2018-12-17T23:11:47.073472682Z 66 PC: 142f2 | Move file pointer
2018-12-17T23:11:47.075872363Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.08367414Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.091309543Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.099723806Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.107499198Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.115779626Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.124508881Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.132190473Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.139660593Z 63 PC: 14293 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T23:11:47.144278485Z 66 PC: 142f2 | Move file pointer
2018-12-17T23:11:47.146258762Z 64 PC: 14293 | Write file or device (Write 9 bytes on handle 5)
2018-12-17T23:11:47.149404326Z 66 PC: 142f2 | Move file pointer
2018-12-17T23:11:47.151452679Z 64 PC: 14293 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T23:11:47.157925437Z 62 PC: 14210 | Close file
2018-12-17T23:11:47.171998705Z 60 PC: 141c0 | Create or truncate file
2018-12-17T23:11:47.183473368Z 64 PC: 14293 | Write file or device (Write 53248 bytes on handle 5)
2018-12-17T23:11:47.196748032Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.205431606Z 62 PC: 14210 | Close file
2018-12-17T23:11:47.21401765Z 65 PC: 14309 | Delete file (Filename = 'A:\tempfall.$$$')
2018-12-17T23:11:47.226020465Z 47 PC: 13a2e | Get disk transfer address
2018-12-17T23:11:47.227364181Z 26 PC: 13a2e | Set disk transfer address
2018-12-17T23:11:47.229514431Z 26 PC: 1399b | Set disk transfer address
2018-12-17T23:11:47.231230995Z 78 PC: 139a7 | Find first file
2018-12-17T23:11:47.237454663Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.247364603Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.249701244Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.25625221Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.259927459Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.261911235Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.264841301Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.267914943Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.270174373Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.273243977Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.276793351Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.278317545Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.281624405Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.284707236Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.291404069Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.294891263Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.298348233Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.300651381Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.303900705Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.307325349Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.309576448Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.317113749Z 26 PC: 13a2e | Set disk transfer address
2018-12-17T23:11:47.318938538Z 47 PC: 13a2e | Get disk transfer address
2018-12-17T23:11:47.321317727Z 26 PC: 13a2e | Set disk transfer address
2018-12-17T23:11:47.323314989Z 26 PC: 1399b | Set disk transfer address
2018-12-17T23:11:47.324641431Z 78 PC: 139a7 | Find first file
2018-12-17T23:11:47.332242954Z 54 PC: 1390a | Get free disk space
2018-12-17T23:11:47.335783863Z 67 PC: 13943 | Get or set file attributes
2018-12-17T23:11:47.342463616Z 67 PC: 1396a | Get or set file attributes
2018-12-17T23:11:47.354117477Z 61 PC: 141c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:47.360663281Z 63 PC: 14293 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:47.374251713Z 66 PC: 142f2 | Move file pointer
2018-12-17T23:11:47.37610126Z 63 PC: 14293 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:47.379346205Z 66 PC: 142f2 | Move file pointer
2018-12-17T23:11:47.381078509Z 63 PC: 14293 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:11:47.383578602Z 66 PC: 142f2 | Move file pointer
2018-12-17T23:11:47.385328244Z 63 PC: 14293 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:47.387695523Z 62 PC: 14210 | Close file
2018-12-17T23:11:47.389389783Z 67 PC: 1396a | Get or set file attributes
2018-12-17T23:11:47.399825266Z 26 PC: 139bf | Set disk transfer address
2018-12-17T23:11:47.400829208Z 79 PC: 139c4 | Find next file
2018-12-17T23:11:47.403434541Z 26 PC: 13a2e | Set disk transfer address
2018-12-17T23:11:47.405796898Z 47 PC: 13a2e | Get disk transfer address
2018-12-17T23:11:47.407082219Z 26 PC: 13a2e | Set disk transfer address
2018-12-17T23:11:47.408345569Z 26 PC: 1399b | Set disk transfer address
2018-12-17T23:11:47.410229118Z 78 PC: 139a7 | Find first file
2018-12-17T23:11:47.417018734Z 26 PC: 13a2e | Set disk transfer address
2018-12-17T23:11:47.418440678Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:47.420516469Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:47.421888427Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:47.423340843Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:47.425466798Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:47.431726402Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:47.432826813Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:47.434881309Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:47.436011454Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:47.437170741Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:47.439009063Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:47.441272003Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:47.442705646Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:47.44488271Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:47.446571594Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:47.448404433Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:47.450213852Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:47.451449903Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:47.452509053Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:47.454323182Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:47.455460418Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:47.456549471Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:47.457808239Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:47.459563699Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:47.460618661Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:47.461720323Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:47.463499689Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:47.464597944Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:47.465680775Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:47.467656184Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:47.468989371Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:47.470364169Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:47.47262322Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:47.473970242Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:47.475251793Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:47.477403535Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:47.479004271Z 53 PC: 13a6b | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:47.480332358Z 37 PC: 13a74 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:47.482597995Z 64 PC: 13f18 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:11:47.484335134Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:47.485457337Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:47.487239198Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:47.488300863Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:47.489405349Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:47.49115781Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:47.492430484Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:47.493777159Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:47.496006861Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:47.497331267Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:47.498631922Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:47.50010694Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:47.502234973Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:47.503585053Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:47.504975584Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:47.506719322Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:47.507790085Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:47.508874301Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:47.510776556Z 37 PC: 13c51 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:47.511863719Z 76 PC: 13c90 | Terminate with return code (Return code = '0')