Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Pech.10736

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:05.131415389Z 53 PC: 1419a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:05.132575439Z 53 PC: 1419a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:05.133738632Z 53 PC: 1419a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:05.13572392Z 53 PC: 1419a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:14:05.136831166Z 53 PC: 1419a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:05.137848978Z 53 PC: 1419a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:05.139306034Z 53 PC: 1419a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:05.140467944Z 53 PC: 1419a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:05.141456277Z 53 PC: 1419a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:05.142854104Z 53 PC: 1419a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:05.143953339Z 53 PC: 1419a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:05.144954796Z 53 PC: 1419a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:05.14640793Z 53 PC: 1419a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:05.147421786Z 53 PC: 1419a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:05.14841211Z 53 PC: 1419a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:05.150048423Z 53 PC: 1419a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:05.151068719Z 53 PC: 1419a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:05.152038105Z 53 PC: 1419a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:14:05.153572335Z 53 PC: 1419a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:14:05.154591289Z 37 PC: 141af | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:05.155498889Z 37 PC: 141b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:05.156693616Z 37 PC: 141bf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:05.157996907Z 37 PC: 141c7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:14:05.159310663Z 68 PC: 14f5f | I/O control for devices (Set for = '')
2018-12-17T22:14:05.200669619Z 37 PC: 13bc1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:05.203190092Z 48 PC: 14c85 | Get DOS version
2018-12-17T22:14:05.205387276Z 48 PC: 14c85 | Get DOS version
2018-12-17T22:14:05.208795858Z 61 PC: 14ac3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:14:05.215317797Z 60 PC: 14ac3 | Create or truncate file
2018-12-17T22:14:05.232187702Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.241287163Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.24921069Z 64 PC: 14b96 | Write file or device (Write 10736 bytes on handle 6)
2018-12-17T22:14:05.257731035Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.26636096Z 64 PC: 14b96 | Write file or device (Write 10736 bytes on handle 6)
2018-12-17T22:14:05.275351501Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.283843617Z 64 PC: 14b96 | Write file or device (Write 10736 bytes on handle 6)
2018-12-17T22:14:05.293363566Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.301102485Z 64 PC: 14b96 | Write file or device (Write 10736 bytes on handle 6)
2018-12-17T22:14:05.308151646Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.316548164Z 64 PC: 14b96 | Write file or device (Write 10736 bytes on handle 6)
2018-12-17T22:14:05.341570172Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.34928837Z 64 PC: 14b96 | Write file or device (Write 8784 bytes on handle 6)
2018-12-17T22:14:05.358329298Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.360319089Z 62 PC: 14b13 | Close file
2018-12-17T22:14:05.36204845Z 62 PC: 14b13 | Close file
2018-12-17T22:14:05.37001411Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:05.372333682Z 37 PC: 13afc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:05.373708492Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:05.375555497Z 37 PC: 13afc | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:05.378380878Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:05.379595892Z 37 PC: 13afc | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:05.380927823Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:14:05.383783768Z 37 PC: 13afc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:14:05.384904064Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:05.386302375Z 37 PC: 13afc | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:05.38788187Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:05.388893541Z 37 PC: 13afc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:05.389882838Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:05.391900067Z 37 PC: 13afc | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:05.393009316Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:05.394033328Z 37 PC: 13afc | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:05.395188491Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:05.396234006Z 37 PC: 13afc | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:05.397317013Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:05.398962936Z 37 PC: 13afc | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:05.400024316Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:05.401236495Z 37 PC: 13afc | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:05.402276711Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:05.404016511Z 37 PC: 13afc | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:05.405560344Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:05.406647873Z 37 PC: 13afc | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:05.407566896Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:05.409050191Z 37 PC: 13afc | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:05.40999903Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:05.411324022Z 37 PC: 13afc | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:05.412685291Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:05.414265088Z 37 PC: 13afc | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:05.415501108Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:05.417156831Z 37 PC: 13afc | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:05.418145959Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:14:05.419369333Z 37 PC: 13afc | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:14:05.421172904Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:14:05.42231478Z 37 PC: 13afc | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:14:05.423516312Z 41 PC: 13aaa | Parse filename
2018-12-17T22:14:05.42512958Z 41 PC: 13ab8 | Parse filename
2018-12-17T22:14:05.426362698Z 75 PC: 13ac3 | Execute program
2018-12-17T22:14:05.443610859Z 9 PC: 1cfdc | Display string (Could not find end pointer)
2018-12-17T22:14:05.449653628Z 76 PC: 1cfe1 | Terminate with return code (Return code = '0')
2018-12-17T22:14:05.452496665Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:05.454094482Z 37 PC: 13afc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:05.45564962Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:05.456721684Z 37 PC: 13afc | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:05.457695532Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:05.459463419Z 37 PC: 13afc | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:05.460879732Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:14:05.462018544Z 37 PC: 13afc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:14:05.463921027Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:05.465086519Z 37 PC: 13afc | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:05.466165514Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:05.467610843Z 37 PC: 13afc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:05.468653813Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:05.470597976Z 37 PC: 13afc | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:05.471829071Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:05.472925522Z 37 PC: 13afc | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:05.474605944Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:05.475679157Z 37 PC: 13afc | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:05.476645606Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:05.478860334Z 37 PC: 13afc | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:05.479931453Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:05.481123045Z 37 PC: 13afc | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:05.497151825Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:05.499350661Z 37 PC: 13afc | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:05.500516682Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:05.502115101Z 37 PC: 13afc | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:05.503284089Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:05.504634697Z 37 PC: 13afc | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:05.506399017Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:05.507415849Z 37 PC: 13afc | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:05.508472016Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:05.511698634Z 37 PC: 13afc | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:05.51314069Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:05.514529636Z 37 PC: 13afc | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:05.516217416Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:14:05.517503871Z 37 PC: 13afc | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:14:05.518860647Z 53 PC: 13af3 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:14:05.521245759Z 37 PC: 13afc | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:14:05.522634323Z 65 PC: 14c0c | Delete file (Filename = 'u)')
2018-12-17T22:14:05.5360609Z 48 PC: 14c85 | Get DOS version
2018-12-17T22:14:05.538229378Z 61 PC: 14ac3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:14:05.544789364Z 63 PC: 14b96 | Read file or device (Read 10736 bytes on handle 5)
2018-12-17T22:14:05.553236919Z 62 PC: 14b13 | Close file
2018-12-17T22:14:05.555259665Z 53 PC: 13a0e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:14:05.5570805Z 37 PC: 13a2a | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:14:05.570419339Z 49 PC: 13a45 | Terminate and stay resident (Return code = '0' | Memory size = '2642')