Sample viewer

vx.netlux.org/Virus.DOS.HLLC.4416

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:15:54.20663858Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:15:54.209682287Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:15:54.211290161Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:15:54.212845903Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:15:54.215043773Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:54.217818875Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:54.220102989Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:15:54.222648721Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:15:54.224863253Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:15:54.226474628Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:15:54.227909314Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:15:54.230006156Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:15:54.231244314Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:15:54.232473416Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:15:54.234470753Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:15:54.235539061Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:15:54.23658576Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:15:54.23790906Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:15:54.23902505Z 53 PC: 12f8a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:15:54.240261843Z 37 PC: 12f9f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:15:54.241958065Z 37 PC: 12fa7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:54.243511771Z 37 PC: 12faf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:54.245032884Z 37 PC: 12fb7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:15:54.246953379Z 68 PC: 13875 | I/O control for devices (Set for = '')
2018-12-17T22:15:54.248862023Z 48 PC: 1359b | Get DOS version
2018-12-17T22:15:54.251429917Z 61 PC: 1344d | Open file (Filename = 'A:\TEST.exe')
2018-12-17T22:15:54.265066988Z 62 PC: 1349d | Close file
2018-12-17T22:15:54.267634182Z 41 PC: 12eef | Parse filename
2018-12-17T22:15:54.269012159Z 41 PC: 12efd | Parse filename
2018-12-17T22:15:54.270386121Z 75 PC: 12f08 | Execute program
2018-12-17T22:15:54.291251322Z 80 PC: 19049 | Set current PSP
2018-12-17T22:15:54.292276692Z 48 PC: 1904e | Get DOS version
2018-12-17T22:15:54.293995015Z 99 PC: 1f830 | Get DBCS lead byte table pointer
2018-12-17T22:15:54.297102016Z 101 PC: 190d4 | Get extended country info
2018-12-17T22:15:54.298443624Z 99 PC: 190da | Get DBCS lead byte table pointer
2018-12-17T22:15:54.299725016Z 74 PC: 1913c | Reallocate memory
2018-12-17T22:15:54.302260326Z 25 PC: 19173 | Get default drive
2018-12-17T22:15:54.303574958Z 37 PC: 18c33 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:15:54.305607616Z 37 PC: 18c3a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:54.307672052Z 37 PC: 18c41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:54.312119689Z 74 PC: 17ddc | Reallocate memory
2018-12-17T22:15:54.313876223Z 72 PC: 17e1d | Allocate memory
2018-12-17T22:15:54.320147959Z 72 PC: 17e55 | Allocate memory
2018-12-17T22:15:54.321992904Z 72 PC: 17e5d | Allocate memory