Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Kuzin.12978

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:12:01.663780718Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:12:01.665990985Z 53 PC: 12bf2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:12:01.667061304Z 53 PC: 12bff | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:12:01.668073074Z 53 PC: 12c0c | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:12:01.669674542Z 53 PC: 12c19 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:12:01.670691089Z 37 PC: 12c2d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:12:01.6718514Z 74 PC: 12af7 | Reallocate memory
2018-12-17T22:12:01.67413662Z 68 PC: 138d6 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:12:01.675964594Z 68 PC: 138d6 | I/O control for devices (Set for = '')
2018-12-17T22:12:01.683729482Z 42 PC: 1366f | Get date 0x1366f: mov byte ptr [si + 4], al
0x13672: mov byte ptr [si], dl
0x13674: mov byte ptr [si + 1], dh
0x13677: mov word ptr [si + 2], cx
0x1367a: pop si
0x1367b: pop bp
0x1367c: ret
0x1367d: push bp
0x1367e: mov bp, sp
0x13680: push si
0x13681: mov si, word ptr [bp + 4]
0x13684: mov ah, 0x2c
0x13686: int 0x21
0x13688: mov byte ptr [si], ch
0x1368a: mov byte ptr [si + 1], cl
0x1368d: mov byte ptr [si + 2], dh
0x13690: mov byte ptr [si + 3], dl
0x13693: pop si
0x13694: pop bp
0x13695: ret
2018-12-17T22:12:01.686548674Z 25 PC: 136a1 | Get default drive
2018-12-17T22:12:01.687643604Z 71 PC: 13757 | Get current directory
2018-12-17T22:12:01.69035304Z 47 PC: 1360c | Get disk transfer address
2018-12-17T22:12:01.694987136Z 26 PC: 13615 | Set disk transfer address
2018-12-17T22:12:01.696039498Z 78 PC: 1361f | Find first file
2018-12-17T22:12:01.70161911Z 26 PC: 13628 | Set disk transfer address
2018-12-17T22:12:01.703316494Z 67 PC: 151bd | Get or set file attributes
2018-12-17T22:12:01.708877033Z 61 PC: 15a7c | Open file (Filename = '')
2018-12-17T22:12:01.715085727Z 68 PC: 14737 | I/O control for devices (Set for = 'fF')
2018-12-17T22:12:01.716498594Z 68 PC: 138d6 | I/O control for devices
2018-12-17T22:12:01.718379904Z 66 PC: 13994 | Move file pointer
2018-12-17T22:12:01.719773671Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.726589684Z 62 PC: 151f8 | Close file
2018-12-17T22:12:01.728291891Z 47 PC: 1363f | Get disk transfer address
2018-12-17T22:12:01.729155086Z 26 PC: 13648 | Set disk transfer address
2018-12-17T22:12:01.730117443Z 79 PC: 1364c | Find next file
2018-12-17T22:12:01.732237574Z 26 PC: 13655 | Set disk transfer address
2018-12-17T22:12:01.733428371Z 59 PC: 134cd | Change current directory
2018-12-17T22:12:01.74016407Z 59 PC: 134cd | Change current directory
2018-12-17T22:12:01.743301437Z 67 PC: 151bd | Get or set file attributes
2018-12-17T22:12:01.748681675Z 61 PC: 15a7c | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:12:01.752719484Z 68 PC: 14737 | I/O control for devices (Set for = '')
2018-12-17T22:12:01.754493142Z 68 PC: 138d6 | I/O control for devices (Set for = '')
2018-12-17T22:12:01.75624469Z 66 PC: 13994 | Move file pointer
2018-12-17T22:12:01.757841537Z 66 PC: 13994 | Move file pointer
2018-12-17T22:12:01.759263817Z 66 PC: 13994 | Move file pointer
2018-12-17T22:12:01.760750424Z 66 PC: 13994 | Move file pointer
2018-12-17T22:12:01.762605303Z 67 PC: 151bd | Get or set file attributes
2018-12-17T22:12:01.768275349Z 60 PC: 158e9 | Create or truncate file
2018-12-17T22:12:01.786119704Z 68 PC: 138d6 | I/O control for devices (Set for = '')
2018-12-17T22:12:01.788105879Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.795586377Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.80223176Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.811399729Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.818395917Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.827035258Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.833885032Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.842782734Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.849689739Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.859858531Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.867277743Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.875841071Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.882624338Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.891549496Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.898306998Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.906792354Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.913727605Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.922454481Z 63 PC: 13aa8 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:12:01.929576004Z 64 PC: 1667c | Write file or device (Write 512 bytes on handle 6)
2018-12-17T22:12:01.939262653Z 64 PC: 1667c | Write file or device (Write 395 bytes on handle 6)
2018-12-17T22:12:01.94304028Z 62 PC: 151f8 | Close file
2018-12-17T22:12:01.951720538Z 62 PC: 151f8 | Close file
2018-12-17T22:12:01.954109708Z 67 PC: 151bd | Get or set file attributes
2018-12-17T22:12:01.962849519Z 60 PC: 158e9 | Create or truncate file
2018-12-17T22:12:01.973695314Z 68 PC: 138d6 | I/O control for devices
2018-12-17T22:12:01.976835133Z 64 PC: 1667c | Write file or device (Write 51 bytes on handle 5)
2018-12-17T22:12:01.980872524Z 62 PC: 151f8 | Close file
2018-12-17T22:12:01.989675052Z 55 PC: 137c0 | Get or set switch character
2018-12-17T22:12:01.993205457Z 41 PC: 14f79 | Parse filename
2018-12-17T22:12:01.994584749Z 41 PC: 14f98 | Parse filename
2018-12-17T22:12:01.996412186Z 75 PC: 14fd8 | Execute program
2018-12-17T22:12:02.018395153Z 80 PC: 27dc9 | Set current PSP
2018-12-17T22:12:02.019192966Z 48 PC: 27dce | Get DOS version
2018-12-17T22:12:02.020681709Z 99 PC: 2e5b0 | Get DBCS lead byte table pointer
2018-12-17T22:12:02.02478353Z 101 PC: 27e54 | Get extended country info
2018-12-17T22:12:02.026261279Z 99 PC: 27e5a | Get DBCS lead byte table pointer
2018-12-17T22:12:02.027670409Z 74 PC: 27ebc | Reallocate memory
2018-12-17T22:12:02.030139771Z 25 PC: 27ef3 | Get default drive
2018-12-17T22:12:02.031164407Z 37 PC: 279b3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:12:02.03220939Z 37 PC: 279ba | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:12:02.034555025Z 37 PC: 279c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:02.03859635Z 74 PC: 26b5c | Reallocate memory
2018-12-17T22:12:02.039856713Z 72 PC: 26b9d | Allocate memory
2018-12-17T22:12:02.042472705Z 72 PC: 26bd5 | Allocate memory
2018-12-17T22:12:02.043988232Z 72 PC: 26bdd | Allocate memory