Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Nover.8640

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:17.604238874Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:17.606860955Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:17.608292236Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:17.609700805Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:17.611864504Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:17.614313419Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:17.616688505Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:17.619053462Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:17.622104018Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:17.623656989Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:17.625137413Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:17.627954109Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:17.630068365Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:17.632124251Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:17.63580387Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:17.637281108Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:17.638743428Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:17.641222119Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:17.642712151Z 53 PC: 13c1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:12:17.644520371Z 37 PC: 13c2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:17.646932878Z 37 PC: 13c37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:17.648345193Z 37 PC: 13c3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:17.64968342Z 37 PC: 13c47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:17.662246224Z 68 PC: 1478f | I/O control for devices (Set for = '')
2018-12-17T23:12:17.665969125Z 53 PC: 13a5f | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:17.667579954Z 37 PC: 13a7b | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:17.669021204Z 53 PC: 13a5f | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:12:17.672036625Z 37 PC: 13a7b | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:12:17.673483836Z 53 PC: 13a5f | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:17.675339726Z 37 PC: 13a7b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:17.682226476Z 51 PC: 1394d | Get or set Ctrl-Break
2018-12-17T23:12:17.683538082Z 48 PC: 144a2 | Get DOS version
2018-12-17T23:12:17.685031861Z 48 PC: 144a2 | Get DOS version
2018-12-17T23:12:17.687835343Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:17.688991608Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:17.695811863Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.71687491Z 60 PC: 142e0 | Create or truncate file
2018-12-17T23:12:17.729782182Z 65 PC: 14429 | Delete file (Filename = 'A:\�')
2018-12-17T23:12:17.741864923Z 61 PC: 142e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:12:17.74982444Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:17.752177775Z 63 PC: 143b3 | Read file or device (Read 5 bytes on handle 6)
2018-12-17T23:12:17.75555708Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.758596746Z 61 PC: 142e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:12:17.767558267Z 63 PC: 143b3 | Read file or device (Read 8640 bytes on handle 6)
2018-12-17T23:12:17.776441051Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.779191393Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:17.781739565Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:17.789111768Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.800246867Z 61 PC: 142e0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:17.808435696Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.811666612Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.822627553Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:17.824970549Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:17.828709319Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.843208424Z 61 PC: 142e0 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:12:17.851107979Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.854134099Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.864646327Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:17.865838719Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:17.870063914Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.880573958Z 61 PC: 142e0 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:12:17.888213684Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.892124458Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.9061118Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:17.907832095Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:17.91210473Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.924157284Z 61 PC: 142e0 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:12:17.931937905Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.935369028Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.946064129Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:17.947611499Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:17.952048963Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.963081169Z 61 PC: 142e0 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:12:17.975869396Z 62 PC: 14330 | Close file
2018-12-17T23:12:17.978990585Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:17.989280385Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:17.990467126Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:17.993921452Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.005057893Z 61 PC: 142e0 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:12:18.01233645Z 62 PC: 14330 | Close file
2018-12-17T23:12:18.014856689Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.02552473Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:18.026741989Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:18.030493754Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.042396897Z 61 PC: 142e0 | Open file (Filename = 'PAH.COM')
2018-12-17T23:12:18.049765994Z 62 PC: 14330 | Close file
2018-12-17T23:12:18.052584855Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.064407226Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:18.066441892Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:18.074050831Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:18.076721683Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:18.083749078Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.094338881Z 61 PC: 142e0 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:12:18.10740962Z 62 PC: 14330 | Close file
2018-12-17T23:12:18.111429148Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.12201286Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:18.123509314Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:18.132000341Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:18.133299053Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:18.139527035Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.481431296Z 61 PC: 142e0 | Open file (Filename = 'c:COMMAND.COM')
2018-12-17T23:12:18.488698722Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.490591842Z 63 PC: 143b3 | Read file or device (Read 5 bytes on handle 6)
2018-12-17T23:12:18.498580054Z 62 PC: 14330 | Close file
2018-12-17T23:12:18.501946344Z 61 PC: 142e0 | Open file (Filename = 'c:COMMAND.COM')
2018-12-17T23:12:18.509278401Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.511220153Z 63 PC: 143b3 | Read file or device (Read 1500 bytes on handle 6)
2018-12-17T23:12:18.519311338Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.521592096Z 64 PC: 143b3 | Write file or device (Write 1500 bytes on handle 6)
2018-12-17T23:12:18.53323466Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.536801156Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.538894823Z 63 PC: 143b3 | Read file or device (Read 1500 bytes on handle 6)
2018-12-17T23:12:18.547764863Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.550743975Z 63 PC: 143b3 | Read file or device (Read 1500 bytes on handle 6)
2018-12-17T23:12:18.557231795Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.558874123Z 64 PC: 143b3 | Write file or device (Write 1500 bytes on handle 6)
2018-12-17T23:12:18.57447505Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.576965423Z 64 PC: 143b3 | Write file or device (Write 1500 bytes on handle 6)
2018-12-17T23:12:18.588744713Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.591544868Z 63 PC: 143b3 | Read file or device (Read 8640 bytes on handle 6)
2018-12-17T23:12:18.600744378Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.603937031Z 64 PC: 143b3 | Write file or device (Write 8640 bytes on handle 6)
2018-12-17T23:12:18.61447125Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.616429513Z 64 PC: 143b3 | Write file or device (Write 8640 bytes on handle 6)
2018-12-17T23:12:18.67982845Z 87 PC: 139ce | Get or set file date and time
2018-12-17T23:12:18.681895628Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.751625631Z 62 PC: 14330 | Close file
2018-12-17T23:12:18.778124019Z 26 PC: 13a22 | Set disk transfer address
2018-12-17T23:12:18.779942018Z 79 PC: 13a27 | Find next file
2018-12-17T23:12:18.785411203Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:18.789261763Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:18.795809326Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:18.798369239Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:18.802792948Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:18.804786106Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:18.811549975Z 37 PC: 13a7b | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:18.815074503Z 37 PC: 13a7b | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:12:18.81696651Z 37 PC: 13a7b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:18.819884948Z 26 PC: 139fe | Set disk transfer address
2018-12-17T23:12:18.822063766Z 78 PC: 13a0a | Find first file
2018-12-17T23:12:18.830243337Z 61 PC: 142e0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:12:18.839671085Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.841849562Z 63 PC: 143b3 | Read file or device (Read 8640 bytes on handle 6)
2018-12-17T23:12:18.85112293Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.853859235Z 64 PC: 14311 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:12:18.864720539Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.866468606Z 64 PC: 143b3 | Write file or device (Write 8640 bytes on handle 6)
2018-12-17T23:12:18.876544674Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.879209234Z 63 PC: 143b3 | Read file or device (Read 1500 bytes on handle 6)
2018-12-17T23:12:18.887856385Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.889816891Z 63 PC: 143b3 | Read file or device (Read 1500 bytes on handle 6)
2018-12-17T23:12:18.902289677Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.904379987Z 64 PC: 143b3 | Write file or device (Write 1500 bytes on handle 6)
2018-12-17T23:12:18.91396435Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.917095538Z 64 PC: 143b3 | Write file or device (Write 1500 bytes on handle 6)
2018-12-17T23:12:18.92604668Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.927683148Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.930712935Z 63 PC: 143b3 | Read file or device (Read 1500 bytes on handle 6)
2018-12-17T23:12:18.938871346Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.940510048Z 64 PC: 143b3 | Write file or device (Write 1500 bytes on handle 6)
2018-12-17T23:12:18.949829733Z 66 PC: 14412 | Move file pointer
2018-12-17T23:12:18.951504021Z 87 PC: 139ce | Get or set file date and time
2018-12-17T23:12:18.953707996Z 67 PC: 13987 | Get or set file attributes
2018-12-17T23:12:18.966740723Z 62 PC: 14330 | Close file
2018-12-17T23:12:18.975081788Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:18.976781815Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:18.979346377Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:18.981099844Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:18.982789452Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:18.985413426Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:18.987151785Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:18.989286439Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:18.991712401Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:18.993312119Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:18.994865159Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:18.997289979Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:18.999109661Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:19.000740337Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:19.003130792Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:19.004920267Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:19.007307386Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:19.009100728Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:19.011387217Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:19.013025979Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:19.014597945Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:19.017082787Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:19.018609228Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:19.020188968Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:19.022319384Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:19.023903533Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:19.025443379Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:19.027989597Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:19.029574627Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:19.031143428Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:19.033229049Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:19.034790265Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:19.036318429Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:19.038842335Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:19.040406005Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:19.041999071Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:19.044504823Z 53 PC: 13b98 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:12:19.050780664Z 37 PC: 13ba1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:12:19.053035323Z 41 PC: 13b4f | Parse filename
2018-12-17T23:12:19.056199413Z 41 PC: 13b5d | Parse filename
2018-12-17T23:12:19.058801225Z 75 PC: 13b68 | Execute program