Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Arj.7952

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:55.917981072Z 53 PC: 13962 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:55.920272749Z 53 PC: 13962 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:18:55.922167466Z 53 PC: 13962 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:55.923595931Z 53 PC: 13962 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:55.925029962Z 53 PC: 13962 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:55.927514879Z 53 PC: 13962 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:55.92900607Z 53 PC: 13962 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:18:55.930539672Z 53 PC: 13962 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:18:55.932555971Z 53 PC: 13962 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:18:55.933797896Z 53 PC: 13962 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:18:55.9350666Z 53 PC: 13962 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:18:55.936818707Z 53 PC: 13962 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:18:55.938495273Z 53 PC: 13962 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:18:55.940139154Z 53 PC: 13962 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:18:55.943212489Z 53 PC: 13962 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:18:55.944986339Z 53 PC: 13962 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:18:55.946541815Z 53 PC: 13962 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:18:55.948514556Z 53 PC: 13962 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:55.950257603Z 53 PC: 13962 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:18:55.951986496Z 37 PC: 13977 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:55.953846898Z 37 PC: 1397f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:55.955452961Z 37 PC: 13987 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:55.957764377Z 37 PC: 1398f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:55.959506181Z 68 PC: 13cff | I/O control for devices (Set for = '')
2018-12-17T22:18:55.961525914Z 48 PC: 1447e | Get DOS version
2018-12-17T22:18:55.963441217Z 25 PC: 1450b | Get default drive
2018-12-17T22:18:55.964656509Z 71 PC: 1451e | Get current directory
2018-12-17T22:18:55.968757819Z 59 PC: 145d2 | Change current directory
2018-12-17T22:18:55.973599643Z 44 PC: 1424b | Get time 0x1424b: mov word ptr [0x3e], cx
0x1424f: mov word ptr [0x40], dx
0x14253: retf
0x14254: mov bx, sp
0x14256: push ds
0x14257: les di, ptr ss:[bx + 8]
0x1425b: lds si, ptr ss:[bx + 4]
0x1425f: cld
0x14260: xor ax, ax
0x14262: stosw word ptr es:[di], ax
0x14263: mov ax, 0xd7b0
0x14266: stosw word ptr es:[di], ax
0x14267: xor ax, ax
0x14269: mov cx, 0x16
0x1426c: rep stosd dword ptr es:[di], eax
0x1426e: lodsb al, byte ptr [si]
0x1426f: cmp al, 0x4f
0x14271: jbe 0x14275
0x14273: mov al, 0x4f
0x14275: mov cl, al
2018-12-17T22:18:55.977203488Z 67 PC: 13729 | Get or set file attributes
2018-12-17T22:18:55.985348232Z 67 PC: 13729 | Get or set file attributes
2018-12-17T22:18:55.997106099Z 67 PC: 13729 | Get or set file attributes
2018-12-17T22:18:56.004879568Z 67 PC: 13729 | Get or set file attributes
2018-12-17T22:18:56.013574559Z 26 PC: 135d5 | Set disk transfer address
2018-12-17T22:18:56.015722706Z 78 PC: 135e1 | Find first file
2018-12-17T22:18:56.023923709Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.025738903Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.028800923Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.029938683Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.033471212Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.0350976Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.038176687Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.040331758Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.043386767Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.044461141Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.047817689Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.056820808Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.059987482Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.061339221Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.065157563Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.066529739Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.069537642Z 26 PC: 135f9 | Set disk transfer address
2018-12-17T22:18:56.071854289Z 79 PC: 135fe | Find next file
2018-12-17T22:18:56.075015526Z 14 PC: 14564 | Set default drive (Drive = 'A')
2018-12-17T22:18:56.076801238Z 25 PC: 14568 | Get default drive
2018-12-17T22:18:56.07885973Z 59 PC: 145d2 | Change current directory
2018-12-17T22:18:56.083711879Z 61 PC: 142ca | Open file (Filename = 'TEST.EXE')
2018-12-17T22:18:56.090955481Z 65 PC: 14413 | Delete file (Filename = 'TEST.EXE')
2018-12-17T22:18:56.112034482Z 86 PC: 14449 | Rename file
2018-12-17T22:18:56.119559581Z 53 PC: 1363c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:56.120835055Z 37 PC: 13645 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:56.122542268Z 53 PC: 1363c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:18:56.123867767Z 37 PC: 13645 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:18:56.125190632Z 53 PC: 1363c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:56.127040183Z 37 PC: 13645 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:56.128822905Z 53 PC: 1363c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:56.130194269Z 37 PC: 13645 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:56.132150747Z 53 PC: 1363c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:56.133499933Z 37 PC: 13645 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:56.134728756Z 53 PC: 1363c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:56.136111357Z 37 PC: 13645 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:56.137495338Z 53 PC: 1363c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:18:56.138673057Z 37 PC: 13645 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:18:56.139789413Z 53 PC: 1363c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:18:56.14119785Z 37 PC: 13645 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:18:56.142315739Z 53 PC: 1363c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:18:56.143482182Z 37 PC: 13645 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:18:56.145260592Z 53 PC: 1363c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:18:56.14641234Z 37 PC: 13645 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:18:56.147536251Z 53 PC: 1363c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:18:56.149260268Z 37 PC: 13645 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:18:56.150455525Z 53 PC: 1363c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:18:56.151644063Z 37 PC: 13645 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:18:56.153479837Z 53 PC: 1363c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:18:56.154658702Z 37 PC: 13645 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:18:56.155761783Z 53 PC: 1363c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:18:56.157571999Z 37 PC: 13645 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:18:56.15903538Z 53 PC: 1363c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:18:56.160393767Z 37 PC: 13645 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:18:56.162118776Z 53 PC: 1363c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:18:56.163331363Z 37 PC: 13645 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:18:56.164521991Z 53 PC: 1363c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:18:56.166682452Z 37 PC: 13645 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:18:56.16792598Z 53 PC: 1363c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:56.169067326Z 37 PC: 13645 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:56.170856482Z 53 PC: 1363c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:18:56.172107721Z 37 PC: 13645 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:18:56.173445849Z 41 PC: 136c5 | Parse filename
2018-12-17T22:18:56.176496188Z 41 PC: 136d3 | Parse filename
2018-12-17T22:18:56.178686588Z 75 PC: 136de | Execute program
2018-12-17T22:18:56.185581432Z 53 PC: 1363c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:56.187312926Z 37 PC: 13645 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:56.188451494Z 53 PC: 1363c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:18:56.189430876Z 37 PC: 13645 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:18:56.191174407Z 53 PC: 1363c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:56.192808715Z 37 PC: 13645 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:56.193917063Z 53 PC: 1363c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:56.19506177Z 37 PC: 13645 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:56.19648962Z 53 PC: 1363c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:56.197421117Z 37 PC: 13645 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:56.19832395Z 53 PC: 1363c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:56.199759044Z 37 PC: 13645 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:56.200638476Z 53 PC: 1363c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:18:56.20157483Z 37 PC: 13645 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:18:56.203396269Z 53 PC: 1363c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:18:56.2045116Z 37 PC: 13645 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:18:56.205715322Z 53 PC: 1363c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:18:56.207122355Z 37 PC: 13645 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:18:56.208051877Z 53 PC: 1363c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:18:56.209280295Z 37 PC: 13645 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:18:56.210742775Z 53 PC: 1363c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:18:56.211702489Z 37 PC: 13645 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:18:56.212587845Z 53 PC: 1363c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:18:56.213783812Z 37 PC: 13645 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:18:56.214945599Z 53 PC: 1363c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:18:56.2159476Z 37 PC: 13645 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:18:56.217252896Z 53 PC: 1363c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:18:56.218288229Z 37 PC: 13645 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:18:56.219294589Z 53 PC: 1363c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:18:56.22072308Z 37 PC: 13645 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:18:56.221813384Z 53 PC: 1363c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:18:56.222816701Z 37 PC: 13645 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:18:56.224353247Z 53 PC: 1363c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:18:56.225309246Z 37 PC: 13645 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:18:56.22627266Z 53 PC: 1363c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:56.227645217Z 37 PC: 13645 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:56.22853443Z 53 PC: 1363c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:18:56.229568143Z 37 PC: 13645 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:18:56.231283793Z 64 PC: 13e02 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:18:56.232572111Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:18:56.233386081Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:18:56.24668224Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:18:56.247873797Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:56.249408606Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:56.251866446Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:56.252762943Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:18:56.253670981Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:18:56.25514788Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:18:56.256765969Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:18:56.258366528Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:18:56.260468011Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:18:56.261910002Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:18:56.263402934Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:18:56.265379575Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:18:56.267010606Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:18:56.268402453Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:18:56.270529955Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:18:56.272119431Z 37 PC: 13a76 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:18:56.273701219Z 76 PC: 13ab5 | Terminate with return code (Return code = '0')