Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Rsw.5846.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:12:30.598887474Z 53 PC: 13832 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:12:30.600547694Z 53 PC: 13832 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:12:30.602329426Z 53 PC: 13832 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:12:30.60343745Z 53 PC: 13832 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:12:30.605196135Z 53 PC: 13832 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:12:30.606372185Z 53 PC: 13832 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:30.607422593Z 53 PC: 13832 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:12:30.608881191Z 53 PC: 13832 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:12:30.610546998Z 53 PC: 13832 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:12:30.611699009Z 53 PC: 13832 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:12:30.61294639Z 53 PC: 13832 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:12:30.614176774Z 53 PC: 13832 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:12:30.615206685Z 53 PC: 13832 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:12:30.616222541Z 53 PC: 13832 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:12:30.618189093Z 53 PC: 13832 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:12:30.619347055Z 53 PC: 13832 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:12:30.620510655Z 53 PC: 13832 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:12:30.62234064Z 53 PC: 13832 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:12:30.623481787Z 53 PC: 13832 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:12:30.624633368Z 37 PC: 13847 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:12:30.626234246Z 37 PC: 1384f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:12:30.627564462Z 37 PC: 13857 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:30.628870964Z 37 PC: 1385f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:12:30.632001733Z 68 PC: 13e32 | I/O control for devices (Set for = '')
2018-12-17T22:12:30.63355951Z 42 PC: 134b7 | Get date 0x134b7: xor ah, ah
0x134b9: les di, ptr [bp + 6]
0x134bc: stosw word ptr es:[di], ax
0x134bd: mov al, dl
0x134bf: les di, ptr [bp + 0xa]
0x134c2: stosw word ptr es:[di], ax
0x134c3: mov al, dh
0x134c5: les di, ptr [bp + 0xe]
0x134c8: stosw word ptr es:[di], ax
0x134c9: xchg ax, cx
0x134ca: les di, ptr [bp + 0x12]
0x134cd: stosw word ptr es:[di], ax
0x134ce: pop bp
0x134cf: retf 0x10
0x134d2: push bp
0x134d3: mov bp, sp
0x134d5: mov cx, word ptr [bp + 0xa]
0x134d8: mov dh, byte ptr [bp + 8]
0x134db: mov dl, byte ptr [bp + 6]
0x134de: mov ah, 0x2b
2018-12-17T22:12:30.635919718Z 64 PC: 13f35 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:12:30.64209996Z 64 PC: 13f35 | Write file or device (Write 36 bytes on handle 1)
2018-12-17T22:12:30.648732281Z 64 PC: 13f35 | Write file or device (Write 53 bytes on handle 1)
2018-12-17T22:12:30.655213626Z 64 PC: 13f35 | Write file or device (Write 28 bytes on handle 1)
2018-12-17T22:12:30.661020723Z 64 PC: 13f35 | Write file or device (Write 39 bytes on handle 1)
2018-12-17T22:12:30.666858999Z 64 PC: 13f35 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:12:30.668508281Z 37 PC: 13946 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:12:30.670207511Z 37 PC: 13946 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:12:30.671418321Z 37 PC: 13946 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:12:30.672579529Z 37 PC: 13946 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:12:30.674160158Z 37 PC: 13946 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:12:30.676035703Z 37 PC: 13946 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:30.677304893Z 37 PC: 13946 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:12:30.679761966Z 37 PC: 13946 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:12:30.681056946Z 37 PC: 13946 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:12:30.682283494Z 37 PC: 13946 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:12:30.684156324Z 37 PC: 13946 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:12:30.685423957Z 37 PC: 13946 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:12:30.687415487Z 37 PC: 13946 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:12:30.689678814Z 37 PC: 13946 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:12:30.690761883Z 37 PC: 13946 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:12:30.692349049Z 37 PC: 13946 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:12:30.694115223Z 37 PC: 13946 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:12:30.698566133Z 37 PC: 13946 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:12:30.700218645Z 37 PC: 13946 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:12:30.701983293Z 76 PC: 13985 | Terminate with return code (Return code = '0')