Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5938.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:26.583188041Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:14:26.5858315Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:26.586945992Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:14:26.587856114Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:14:26.589491562Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:14:26.590526525Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:26.591473084Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:14:26.595474161Z 67 PC: 13953 | Get or set file attributes
2018-12-17T22:14:26.601083813Z 67 PC: 13953 | Get or set file attributes
2018-12-17T22:14:26.616966402Z 61 PC: 13786 | Open file (Filename = '')
2018-12-17T22:14:26.621870659Z 68 PC: 137bb | I/O control for devices (Set for = '&�M#�')
2018-12-17T22:14:26.623347551Z 66 PC: 13ab0 | Move file pointer
2018-12-17T22:14:26.624458725Z 66 PC: 13abd | Move file pointer
2018-12-17T22:14:26.625911037Z 66 PC: 13acc | Move file pointer
2018-12-17T22:14:26.62709039Z 87 PC: 142b4 | Get or set file date and time
2018-12-17T22:14:26.628337415Z 66 PC: 13875 | Move file pointer
2018-12-17T22:14:26.629877406Z 63 PC: 13805 | Read file or device (Read 5938 bytes on handle 5)
2018-12-17T22:14:26.635548476Z 62 PC: 137de | Close file
2018-12-17T22:14:26.637266782Z 26 PC: 13ff3 | Set disk transfer address
2018-12-17T22:14:26.641629109Z 78 PC: 13ffd | Find first file
2018-12-17T22:14:26.647283389Z 67 PC: 13953 | Get or set file attributes
2018-12-17T22:14:26.652909223Z 67 PC: 13953 | Get or set file attributes
2018-12-17T22:14:26.663439969Z 61 PC: 13786 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:14:26.669786886Z 68 PC: 137bb | I/O control for devices (Set for = '')
2018-12-17T22:14:26.671240139Z 87 PC: 142b4 | Get or set file date and time
2018-12-17T22:14:26.673089918Z 66 PC: 13875 | Move file pointer
2018-12-17T22:14:26.681354383Z 63 PC: 13805 | Read file or device (Read 5938 bytes on handle 5)
2018-12-17T22:14:26.688367342Z 67 PC: 13953 | Get or set file attributes
2018-12-17T22:14:26.697611556Z 26 PC: 14015 | Set disk transfer address
2018-12-17T22:14:26.699150062Z 79 PC: 14019 | Find next file
2018-12-17T22:14:26.701811064Z 61 PC: 13786 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:14:26.707508526Z 68 PC: 137bb | I/O control for devices (Set for = '')
2018-12-17T22:14:26.708916913Z 66 PC: 13875 | Move file pointer
2018-12-17T22:14:26.709933021Z 63 PC: 13805 | Read file or device (Read 5938 bytes on handle 6)
2018-12-17T22:14:26.714723482Z 66 PC: 13875 | Move file pointer
2018-12-17T22:14:26.715959699Z 64 PC: 1383e | Write file or device (Write 5938 bytes on handle 6)
2018-12-17T22:14:26.721195064Z 62 PC: 137de | Close file
2018-12-17T22:14:26.72712079Z 26 PC: 13ff3 | Set disk transfer address
2018-12-17T22:14:26.728422166Z 78 PC: 13ffd | Find first file
2018-12-17T22:14:26.735873813Z 41 PC: 14643 | Parse filename
2018-12-17T22:14:26.73683394Z 41 PC: 14651 | Parse filename
2018-12-17T22:14:26.738355408Z 75 PC: 14691 | Execute program
2018-12-17T22:14:26.74816693Z 76 PC: 26db7 | Terminate with return code (Return code = '0')
2018-12-17T22:14:26.750042251Z 77 PC: 146b3 | Get program return code
2018-12-17T22:14:26.75176028Z 61 PC: 13786 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:14:26.756022069Z 68 PC: 137bb | I/O control for devices (Set for = '')
2018-12-17T22:14:26.757831853Z 66 PC: 13875 | Move file pointer
2018-12-17T22:14:26.761411838Z 64 PC: 1383e | Write file or device (Write 5938 bytes on handle 6)
2018-12-17T22:14:26.767234559Z 87 PC: 145f9 | Get or set file date and time
2018-12-17T22:14:26.768251974Z 62 PC: 137de | Close file
2018-12-17T22:14:26.77300731Z 67 PC: 13953 | Get or set file attributes
2018-12-17T22:14:26.78486872Z 37 PC: 12bef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:26.786175625Z 37 PC: 12bfa | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:14:26.788238584Z 37 PC: 12c05 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:14:26.789514649Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:14:26.790995802Z 76 PC: 12b98 | Terminate with return code (Return code = '0')