Sample viewer

vx.netlux.org/Virus.DOS.HLLC.9472

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:06:45.345403147Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:06:45.347214234Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:06:45.348857998Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:06:45.350369407Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:45.352205559Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:45.354220142Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:45.355907924Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:06:45.358111065Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:06:45.365275621Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:06:45.366857847Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:06:45.368396036Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:06:45.369569866Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:06:45.381475334Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:06:45.383578928Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:06:45.385585754Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:06:45.387576746Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:06:45.389856863Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:06:45.391852784Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:06:45.393872156Z 53 PC: 13e22 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:06:45.396271166Z 37 PC: 13e37 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:06:45.3977125Z 37 PC: 13e3f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:45.399275038Z 37 PC: 13e47 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:45.400760851Z 37 PC: 13e4f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:06:45.403065835Z 68 PC: 141bf | I/O control for devices (Set for = '')
2018-12-17T22:06:45.405691375Z 14 PC: 14adc | Set default drive (Drive = 'D')
2018-12-17T22:06:45.407768015Z 25 PC: 14ae0 | Get default drive
2018-12-17T22:06:45.409888745Z 26 PC: 13a1f | Set disk transfer address
2018-12-17T22:06:45.416360776Z 78 PC: 13a2b | Find first file
2018-12-17T22:06:45.422936809Z 61 PC: 141a6 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:06:45.429560232Z 87 PC: 139c2 | Get or set file date and time
2018-12-17T22:06:45.431934283Z 62 PC: 142dc | Close file
2018-12-17T22:06:45.433915266Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.453537548Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.457743347Z 25 PC: 13c5b | Get default drive
2018-12-17T22:06:45.459187792Z 71 PC: 13c7a | Get current directory
2018-12-17T22:06:45.463369448Z 14 PC: 14adc | Set default drive (Drive = 'C')
2018-12-17T22:06:45.466162524Z 25 PC: 14ae0 | Get default drive
2018-12-17T22:06:45.467622347Z 59 PC: 14b4a | Change current directory
2018-12-17T22:06:45.471801649Z 26 PC: 13a1f | Set disk transfer address
2018-12-17T22:06:45.474787942Z 78 PC: 13a2b | Find first file
2018-12-17T22:06:45.480658504Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.482061072Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.4852523Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.487468036Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.490243134Z 44 PC: 147bf | Get time 0x147bf: mov word ptr [0x3e], cx
0x147c3: mov word ptr [0x40], dx
0x147c7: retf
0x147c8: mov bx, sp
0x147ca: push ds
0x147cb: les di, ptr ss:[bx + 8]
0x147cf: lds si, ptr ss:[bx + 4]
0x147d3: cld
0x147d4: xor ax, ax
0x147d6: stosw word ptr es:[di], ax
0x147d7: mov ax, 0xd7b0
0x147da: stosw word ptr es:[di], ax
0x147db: xor ax, ax
0x147dd: mov cx, 0x16
0x147e0: rep stosd dword ptr es:[di], eax
0x147e2: lodsb al, byte ptr [si]
0x147e3: cmp al, 0x4f
0x147e5: jbe 0x147e9
0x147e7: mov al, 0x4f
0x147e9: mov cl, al
2018-12-17T22:06:45.493224253Z 14 PC: 14adc | Set default drive (Drive = 'C')
2018-12-17T22:06:45.495813406Z 25 PC: 14ae0 | Get default drive
2018-12-17T22:06:45.497230261Z 59 PC: 14b4a | Change current directory
2018-12-17T22:06:45.508383839Z 26 PC: 13a1f | Set disk transfer address
2018-12-17T22:06:45.510167223Z 78 PC: 13a2b | Find first file
2018-12-17T22:06:45.518734284Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.519787969Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.52400969Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.525366827Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.52891974Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.532024944Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.535512244Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.536931534Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.54117655Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.542380695Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.548510867Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.550139016Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.553491877Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.55463426Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.558390501Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.5594509Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.562677812Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.564355354Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.56746638Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.568381297Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.572082396Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.572992665Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.576015791Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.577599322Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.580843441Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.58173088Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.584907496Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.586183848Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.58918164Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.590080415Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.596626621Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.597893676Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.60103707Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.602761963Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.606540275Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.607393057Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.61093937Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.612241072Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.615726474Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.61748965Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.620867324Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.622118935Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.626281457Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.627521211Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.630883615Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.632876114Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.639116564Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.64025005Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.644597719Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.645787627Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.648901477Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.65075423Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.653923009Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.654918575Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.658599343Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.659611423Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.662720372Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.66465291Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.670919222Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.67200375Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.679574613Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.680652969Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.686918542Z 26 PC: 13a43 | Set disk transfer address
2018-12-17T22:06:45.688748761Z 79 PC: 13a48 | Find next file
2018-12-17T22:06:45.694902884Z 44 PC: 147bf | Get time 0x147bf: mov word ptr [0x3e], cx
0x147c3: mov word ptr [0x40], dx
0x147c7: retf
0x147c8: mov bx, sp
0x147ca: push ds
0x147cb: les di, ptr ss:[bx + 8]
0x147cf: lds si, ptr ss:[bx + 4]
0x147d3: cld
0x147d4: xor ax, ax
0x147d6: stosw word ptr es:[di], ax
0x147d7: mov ax, 0xd7b0
0x147da: stosw word ptr es:[di], ax
0x147db: xor ax, ax
0x147dd: mov cx, 0x16
0x147e0: rep stosd dword ptr es:[di], eax
0x147e2: lodsb al, byte ptr [si]
0x147e3: cmp al, 0x4f
0x147e5: jbe 0x147e9
0x147e7: mov al, 0x4f
0x147e9: mov cl, al
2018-12-17T22:06:45.697489868Z 61 PC: 1483e | Open file (Filename = 'MSD.EXE')
2018-12-17T22:06:45.704764601Z 66 PC: 149da | Move file pointer
2018-12-17T22:06:45.706078943Z 66 PC: 149e8 | Move file pointer
2018-12-17T22:06:45.707626391Z 66 PC: 149f6 | Move file pointer
2018-12-17T22:06:45.709702534Z 62 PC: 1488e | Close file
2018-12-17T22:06:45.712447742Z 67 PC: 139a8 | Get or set file attributes
2018-12-17T22:06:46.045646864Z 60 PC: 1483e | Create or truncate file
2018-12-17T22:06:46.05683669Z 62 PC: 1488e | Close file
2018-12-17T22:06:46.059377759Z 86 PC: 14a49 | Rename file
2018-12-17T22:06:46.072364024Z 14 PC: 14adc | Set default drive (Drive = 'A')
2018-12-17T22:06:46.073699594Z 25 PC: 14ae0 | Get default drive
2018-12-17T22:06:46.076028503Z 61 PC: 1483e | Open file (Filename = 'emory into which to load the program. Region1 specifies the numbe')
2018-12-17T22:06:46.080868783Z 64 PC: 142c2 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:06:46.082756332Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:06:46.084927791Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:06:46.086010165Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:06:46.087045749Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:46.089152186Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:46.090181894Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:46.091217014Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:06:46.093166989Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:06:46.094241314Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:06:46.095270848Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:06:46.097240442Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:06:46.098282318Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:06:46.099305298Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:06:46.101261978Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:06:46.102512244Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:06:46.103743072Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:06:46.105894766Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:06:46.107073751Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:06:46.108020764Z 37 PC: 13f36 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:06:46.109702494Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.112397079Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.114361639Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.116295139Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.118865637Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.120771961Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.123068457Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.125223088Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.127138046Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.129507145Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.131414164Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.133320477Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.135907076Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.138536301Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.14060764Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.143091041Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.145254023Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.14734375Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.149731359Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.151892481Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.154603321Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.163940212Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.166359515Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.1683172Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.171020403Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.17319498Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.175520514Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.178178133Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.18092569Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.183500592Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.186084036Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.188334966Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.190896784Z 6 PC: 13fbd | Direct console I/O
2018-12-17T22:06:46.194680687Z 76 PC: 13f75 | Terminate with return code (Return code = '2')