Sample viewer

vx.netlux.org/Virus.DOS.HLLP.4512

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:08:01.149019967Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:01.150256925Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:08:01.160285449Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:08:01.161917843Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:01.163529275Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:01.166463141Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:08:01.167782821Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:08:01.169154812Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:08:01.171070804Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:08:01.172647688Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:08:01.174087689Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:08:01.175922439Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:08:01.177766187Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:08:01.179173238Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:08:01.181553523Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:08:01.183002026Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:08:01.184344158Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:08:01.185691856Z 53 PC: 12ea6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:08:01.187773942Z 37 PC: 12ebb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:01.1888508Z 37 PC: 12ec3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:01.189884443Z 37 PC: 12ecb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:01.19166027Z 37 PC: 12ed3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:08:01.193381344Z 68 PC: 134d3 | I/O control for devices (Set for = '')
2018-12-17T22:08:01.195447669Z 26 PC: 12d65 | Set disk transfer address
2018-12-17T22:08:01.197509978Z 78 PC: 12d71 | Find first file
2018-12-17T22:08:01.20386109Z 48 PC: 13847 | Get DOS version
2018-12-17T22:08:01.205567655Z 61 PC: 1366d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:08:01.214075292Z 61 PC: 1366d | Open file (Filename = 'TEST.EXE')
2018-12-17T22:08:01.221373811Z 63 PC: 13740 | Read file or device (Read 4512 bytes on handle 5)
2018-12-17T22:08:01.233878745Z 63 PC: 13740 | Read file or device (Read 4512 bytes on handle 6)
2018-12-17T22:08:01.242087591Z 62 PC: 136bd | Close file
2018-12-17T22:08:01.244142218Z 62 PC: 136bd | Close file
2018-12-17T22:08:01.246089268Z 26 PC: 12d89 | Set disk transfer address
2018-12-17T22:08:01.247837411Z 79 PC: 12d8e | Find next file
2018-12-17T22:08:01.250620113Z 48 PC: 13847 | Get DOS version
2018-12-17T22:08:01.252254427Z 61 PC: 1366d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:08:01.259643723Z 66 PC: 13809 | Move file pointer
2018-12-17T22:08:01.261597771Z 66 PC: 13817 | Move file pointer
2018-12-17T22:08:01.263147872Z 66 PC: 13825 | Move file pointer
2018-12-17T22:08:01.264970761Z 66 PC: 1379f | Move file pointer
2018-12-17T22:08:01.267374562Z 63 PC: 13740 | Read file or device (Read 4512 bytes on handle 5)
2018-12-17T22:08:01.274420536Z 66 PC: 1379f | Move file pointer
2018-12-17T22:08:01.278679026Z 64 PC: 13740 | Write file or device (Write 4512 bytes on handle 5)
2018-12-17T22:08:01.292006748Z 62 PC: 136bd | Close file
2018-12-17T22:08:01.299788802Z 48 PC: 13847 | Get DOS version
2018-12-17T22:08:01.301468893Z 41 PC: 12e1c | Parse filename
2018-12-17T22:08:01.303587038Z 41 PC: 12e2a | Parse filename
2018-12-17T22:08:01.305214076Z 75 PC: 12e35 | Execute program
2018-12-17T22:08:01.31323076Z 48 PC: 13847 | Get DOS version
2018-12-17T22:08:01.315853948Z 61 PC: 1366d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:08:01.322372921Z 64 PC: 13740 | Write file or device (Write 4512 bytes on handle 5)
2018-12-17T22:08:01.330041131Z 62 PC: 136bd | Close file
2018-12-17T22:08:01.338432981Z 64 PC: 135d6 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:08:01.340183782Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:01.341254777Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:08:01.343311843Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:08:01.344505629Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:01.345535709Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:01.349502147Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:08:01.35083436Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:08:01.352166514Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:08:01.354052356Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:08:01.355397545Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:08:01.356705379Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:08:01.358574256Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:08:01.359669671Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:08:01.360971226Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:08:01.362846518Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:08:01.364172887Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:08:01.365480747Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:08:01.367192687Z 37 PC: 12fb5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:08:01.368479022Z 76 PC: 12ff4 | Terminate with return code (Return code = '0')