Sample viewer

vx.netlux.org/Virus.DOS.HLLW.Cubex

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:52.118286202Z 48 PC: 181fc | Get DOS version
2018-12-17T23:12:52.120930133Z 74 PC: 1824c | Reallocate memory
2018-12-17T23:12:52.123517728Z 48 PC: 182b0 | Get DOS version
2018-12-17T23:12:52.125317622Z 53 PC: 182b8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:52.128280613Z 37 PC: 182ca | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:52.130196686Z 53 PC: 1af12 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:52.131566211Z 37 PC: 1af22 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:52.137698562Z 53 PC: 1af27 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:52.139548821Z 37 PC: 1af37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:52.140935598Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:52.142330441Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:52.145269988Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:52.147628463Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:52.149910654Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:52.153224625Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:52.156762537Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:52.170328364Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:52.173303248Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:52.174999628Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:52.176826223Z 53 PC: 18c66 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:52.179904971Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:52.183862673Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:52.185404201Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:52.189652619Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:52.190873495Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:52.193349982Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:52.195861414Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:52.197075326Z 37 PC: 18c95 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:52.198181105Z 37 PC: 18c9c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:52.19965157Z 37 PC: 18ca1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:52.201493253Z 68 PC: 1835b | I/O control for devices (Set for = '�%�!&�(� %�!��Z[X�VW��# ��uW��b:�rN:�rJ:�tF�[�>`�����Î��Ŋ���ÊS�ر��ʇ��� ��r�������')
2018-12-17T23:12:52.202701675Z 68 PC: 1835b | I/O control for devices
2018-12-17T23:12:52.203973246Z 68 PC: 1835b | I/O control for devices (Set for = '\ ���� ] ��.���2�xF �y���ߋD;E|�')
2018-12-17T23:12:52.210413295Z 68 PC: 1835b | I/O control for devices (Set for = 'F �y���ߋD;E|�')
2018-12-17T23:12:52.21234103Z 68 PC: 1835b | I/O control for devices (Set for = 'F �y���ߋD;E|�')
2018-12-17T23:12:52.214603443Z 53 PC: 15814 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:52.217210475Z 53 PC: 15821 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:12:52.219652557Z 53 PC: 1582e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:52.221932894Z 37 PC: 15843 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:52.224152578Z 37 PC: 1584b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:12:52.226210648Z 37 PC: 15853 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:52.228154283Z 53 PC: 162d2 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:12:52.230185732Z 53 PC: 162df | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:12:52.243372557Z 53 PC: 162ee | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:52.245100626Z 37 PC: 162fb | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:12:52.246829647Z 53 PC: 16302 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:12:52.249618561Z 37 PC: 1630f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:12:52.252602591Z 53 PC: 1631b | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:12:52.257549914Z 48 PC: 163dd | Get DOS version
2018-12-17T23:12:52.260343277Z 74 PC: 144df | Reallocate memory
2018-12-17T23:12:52.262653701Z 74 PC: 144df | Reallocate memory
2018-12-17T23:12:52.264622442Z 68 PC: 1578a | I/O control for devices (Set for = '')
2018-12-17T23:12:52.267643703Z 68 PC: 1578a | I/O control for devices (Set for = '')
2018-12-17T23:12:52.269612695Z 51 PC: 157a8 | Get or set Ctrl-Break
2018-12-17T23:12:52.270994523Z 51 PC: 157b4 | Get or set Ctrl-Break
2018-12-17T23:12:52.27507716Z 74 PC: 144df | Reallocate memory
2018-12-17T23:12:52.277341568Z 51 PC: 157bf | Get or set Ctrl-Break
2018-12-17T23:12:52.278756438Z 37 PC: 15a41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:52.280434723Z 37 PC: 15a4b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:12:52.283004966Z 37 PC: 15a55 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:52.285140732Z 53 PC: 13f0c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:12:52.286874953Z 53 PC: 13f19 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:12:52.289200937Z 53 PC: 13f26 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:52.290563659Z 37 PC: 13f41 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:12:52.291842964Z 53 PC: 13f49 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:12:52.29355348Z 37 PC: 13f56 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:52.29521295Z 53 PC: 13f5d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:12:52.29675528Z 37 PC: 13f6a | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:12:52.29887721Z 37 PC: 13f74 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:12:52.30043555Z 37 PC: 13f7f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:12:52.302112794Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:52.309371683Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:52.310773779Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:52.312132073Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:52.314215641Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:52.315627626Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:52.317022148Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:52.319534091Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:52.320902193Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:52.322523552Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:52.32503274Z 37 PC: 18cb1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:52.326645652Z 37 PC: 1af46 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:52.328331412Z 37 PC: 1840c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:52.333830131Z 41 PC: 17fdb | Parse filename
2018-12-17T23:12:52.335567117Z 41 PC: 17fdd | Parse filename
2018-12-17T23:12:52.337303011Z 41 PC: 17fe2 | Parse filename
2018-12-17T23:12:52.339906877Z 75 PC: 17ff8 | Execute program
2018-12-17T23:12:52.364861929Z 80 PC: 1dec9 | Set current PSP
2018-12-17T23:12:52.366156734Z 48 PC: 1dece | Get DOS version
2018-12-17T23:12:52.368794013Z 99 PC: 246b0 | Get DBCS lead byte table pointer
2018-12-17T23:12:52.371658508Z 101 PC: 1df54 | Get extended country info
2018-12-17T23:12:52.373135395Z 99 PC: 1df5a | Get DBCS lead byte table pointer
2018-12-17T23:12:52.375604367Z 74 PC: 1dfbc | Reallocate memory
2018-12-17T23:12:52.377507606Z 25 PC: 1dff3 | Get default drive
2018-12-17T23:12:52.379120499Z 37 PC: 1dab3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:12:52.381528046Z 37 PC: 1daba | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:52.383084903Z 37 PC: 1dac1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:52.387728124Z 74 PC: 1cc5c | Reallocate memory
2018-12-17T23:12:52.390173812Z 72 PC: 1cc9d | Allocate memory
2018-12-17T23:12:52.392509554Z 72 PC: 1ccd5 | Allocate memory
2018-12-17T23:12:52.394465742Z 72 PC: 1ccdd | Allocate memory