Sample viewer

vx.netlux.org/Virus.DOS.HLLC.5472

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:52:12.360976449Z 53 PC: 13276 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.363716917Z 53 PC: 13276 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:12.365003768Z 53 PC: 13276 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:12.366287591Z 53 PC: 13276 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.368115339Z 53 PC: 13276 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.370432711Z 53 PC: 13276 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:12.371637618Z 53 PC: 13276 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:12.373188661Z 53 PC: 13276 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:12.37547348Z 53 PC: 13276 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:12.377551883Z 53 PC: 13276 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:12.379178766Z 53 PC: 13276 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:12.384872514Z 53 PC: 13276 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:12.386441833Z 53 PC: 13276 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:12.388015393Z 53 PC: 13276 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:12.390272023Z 53 PC: 13276 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:12.391785503Z 53 PC: 13276 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:12.393298128Z 53 PC: 13276 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.396048492Z 53 PC: 13276 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:12.397511114Z 37 PC: 1328b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.398933712Z 37 PC: 13293 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.401046332Z 37 PC: 1329b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.40241923Z 37 PC: 132a3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.404211712Z 68 PC: 13883 | I/O control for devices (Set for = '')
2018-12-17T21:52:12.420301641Z 26 PC: 130fb | Set disk transfer address
2018-12-17T21:52:12.427857942Z 78 PC: 13107 | Find first file
2018-12-17T21:52:12.434407571Z 48 PC: 13d59 | Get DOS version
2018-12-17T21:52:12.437642448Z 44 PC: 1371f | Get time 0x1371f: mov word ptr [0x38], cx
0x13723: mov word ptr [0x3a], dx
0x13727: retf
0x13728: mov bx, sp
0x1372a: push ds
0x1372b: les di, ptr ss:[bx + 8]
0x1372f: lds si, ptr ss:[bx + 4]
0x13733: cld
0x13734: xor ax, ax
0x13736: stosw word ptr es:[di], ax
0x13737: mov ax, 0xd7b0
0x1373a: stosw word ptr es:[di], ax
0x1373b: mov ax, 0x80
0x1373e: stosw word ptr es:[di], ax
0x1373f: xor ax, ax
0x13741: stosw word ptr es:[di], ax
0x13742: stosw word ptr es:[di], ax
0x13743: stosw word ptr es:[di], ax
0x13744: lea ax, word ptr [di + 0x74]
0x13747: stosw word ptr es:[di], ax
2018-12-17T21:52:12.440342357Z 26 PC: 130fb | Set disk transfer address
2018-12-17T21:52:12.441761263Z 78 PC: 13107 | Find first file
2018-12-17T21:52:12.44882921Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.450247011Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.453422057Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.45570852Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.467759638Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.469175222Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.47201342Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.473763211Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.476499617Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.477880205Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.483675249Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.484705935Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.486980233Z 26 PC: 1311f | Set disk transfer address
2018-12-17T21:52:12.488714043Z 79 PC: 13124 | Find next file
2018-12-17T21:52:12.491191929Z 61 PC: 13ba5 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:52:12.498049085Z 61 PC: 13ba5 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:52:12.505579413Z 62 PC: 13bf5 | Close file
2018-12-17T21:52:12.507927063Z 61 PC: 13ba5 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:52:12.514687433Z 66 PC: 13cd7 | Move file pointer
2018-12-17T21:52:12.517301415Z 63 PC: 13c78 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T21:52:12.524662385Z 62 PC: 13bf5 | Close file
2018-12-17T21:52:12.527959446Z 53 PC: 13162 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.538877859Z 37 PC: 1316b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.540429005Z 53 PC: 13162 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:12.541968205Z 37 PC: 1316b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:12.544550325Z 53 PC: 13162 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:12.545966946Z 37 PC: 1316b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:12.547258668Z 53 PC: 13162 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.549511886Z 37 PC: 1316b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.550922513Z 53 PC: 13162 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.552476152Z 37 PC: 1316b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.55484495Z 53 PC: 13162 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:12.556626513Z 37 PC: 1316b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:12.558127903Z 53 PC: 13162 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:12.56078161Z 37 PC: 1316b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:12.562418231Z 53 PC: 13162 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:12.564030943Z 37 PC: 1316b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:12.566601957Z 53 PC: 13162 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:12.568226791Z 37 PC: 1316b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:12.569777702Z 53 PC: 13162 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:12.572354533Z 37 PC: 1316b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:12.573964378Z 53 PC: 13162 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:12.575525731Z 37 PC: 1316b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:12.577911794Z 53 PC: 13162 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:12.579585818Z 37 PC: 1316b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:12.581129753Z 53 PC: 13162 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:12.582896171Z 37 PC: 1316b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:12.585533188Z 53 PC: 13162 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:12.587540052Z 37 PC: 1316b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:12.589143836Z 53 PC: 13162 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:12.5909353Z 37 PC: 1316b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:12.592345094Z 53 PC: 13162 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:12.593844348Z 37 PC: 1316b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:12.595816415Z 53 PC: 13162 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.597256696Z 37 PC: 1316b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.598648016Z 53 PC: 13162 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:12.600610678Z 37 PC: 1316b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:12.602453082Z 41 PC: 131ea | Parse filename
2018-12-17T21:52:12.603778281Z 41 PC: 131f8 | Parse filename
2018-12-17T21:52:12.60633281Z 75 PC: 13203 | Execute program
2018-12-17T21:52:12.612858947Z 53 PC: 13162 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.614413532Z 37 PC: 1316b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.61664264Z 53 PC: 13162 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:12.618056369Z 37 PC: 1316b | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:12.619381041Z 53 PC: 13162 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:12.621230647Z 37 PC: 1316b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:12.622776957Z 53 PC: 13162 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.624231108Z 37 PC: 1316b | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.626000484Z 53 PC: 13162 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.62711371Z 37 PC: 1316b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.628655713Z 53 PC: 13162 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:12.630955414Z 37 PC: 1316b | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:12.632322405Z 53 PC: 13162 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:12.633759466Z 37 PC: 1316b | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:12.635766309Z 53 PC: 13162 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:12.637193581Z 37 PC: 1316b | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:12.638563997Z 53 PC: 13162 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:12.640579507Z 37 PC: 1316b | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:12.641894291Z 53 PC: 13162 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:12.643204771Z 37 PC: 1316b | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:12.644753642Z 53 PC: 13162 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:12.646070054Z 37 PC: 1316b | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:12.647421112Z 53 PC: 13162 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:12.650302295Z 37 PC: 1316b | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:12.651617085Z 53 PC: 13162 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:12.655025438Z 37 PC: 1316b | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:12.657129035Z 53 PC: 13162 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:12.658342153Z 37 PC: 1316b | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:12.659585217Z 53 PC: 13162 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:12.662211258Z 37 PC: 1316b | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:12.663404902Z 53 PC: 13162 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:12.664761959Z 37 PC: 1316b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:12.666917088Z 53 PC: 13162 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.668081918Z 37 PC: 1316b | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.669204588Z 53 PC: 13162 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:12.671100242Z 37 PC: 1316b | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:12.672456065Z 64 PC: 13986 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:52:12.674066342Z 37 PC: 13385 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:12.675942441Z 37 PC: 13385 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:12.677174717Z 37 PC: 13385 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:12.678476815Z 37 PC: 13385 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:12.680820375Z 37 PC: 13385 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:12.682130905Z 37 PC: 13385 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:12.683444728Z 37 PC: 13385 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:12.685229311Z 37 PC: 13385 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:12.686490191Z 37 PC: 13385 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:12.687798611Z 37 PC: 13385 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:12.68979793Z 37 PC: 13385 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:12.690926273Z 37 PC: 13385 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:12.69198118Z 37 PC: 13385 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:12.693851529Z 37 PC: 13385 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:12.695164995Z 37 PC: 13385 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:12.696455127Z 37 PC: 13385 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:12.699480669Z 37 PC: 13385 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:12.700622898Z 37 PC: 13385 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:12.701601514Z 76 PC: 133c4 | Terminate with return code (Return code = '0')