Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Kretyn.5776

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:09.197405779Z 53 PC: 1318a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:09.200404642Z 53 PC: 1318a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:09.201696509Z 53 PC: 1318a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:09.203152184Z 53 PC: 1318a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:09.204544134Z 53 PC: 1318a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:09.207116665Z 53 PC: 1318a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:09.208322792Z 53 PC: 1318a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:09.209487755Z 53 PC: 1318a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:09.211598018Z 53 PC: 1318a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:09.213633098Z 53 PC: 1318a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:09.215614663Z 53 PC: 1318a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:09.217589846Z 53 PC: 1318a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:09.219633741Z 53 PC: 1318a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:09.221271856Z 53 PC: 1318a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:09.223749357Z 53 PC: 1318a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:09.225128514Z 53 PC: 1318a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:09.226499715Z 53 PC: 1318a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:09.228819391Z 53 PC: 1318a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:09.230216576Z 53 PC: 1318a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:09.231575928Z 37 PC: 1319f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:09.233898401Z 37 PC: 131a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:09.235206588Z 37 PC: 131af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:09.236476421Z 37 PC: 131b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:09.239349997Z 68 PC: 13d8d | I/O control for devices (Set for = '')
2018-12-17T21:53:09.241826937Z 48 PC: 1399e | Get DOS version
2018-12-17T21:53:09.243438079Z 67 PC: 12eef | Get or set file attributes
2018-12-17T21:53:09.250199869Z 67 PC: 12f16 | Get or set file attributes
2018-12-17T21:53:09.266892308Z 61 PC: 13850 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:53:09.274076205Z 63 PC: 13923 | Read file or device (Read 5776 bytes on handle 5)
2018-12-17T21:53:09.28139029Z 87 PC: 12f5d | Get or set file date and time
2018-12-17T21:53:09.283353342Z 62 PC: 138a0 | Close file
2018-12-17T21:53:09.295097519Z 67 PC: 12f16 | Get or set file attributes
2018-12-17T21:53:09.312010204Z 26 PC: 12f8d | Set disk transfer address
2018-12-17T21:53:09.314288505Z 78 PC: 12f99 | Find first file
2018-12-17T21:53:09.320462708Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T21:53:09.322204457Z 79 PC: 12fb6 | Find next file
2018-12-17T21:53:09.32638693Z 48 PC: 1399e | Get DOS version
2018-12-17T21:53:09.328193533Z 48 PC: 1399e | Get DOS version
2018-12-17T21:53:09.329978391Z 67 PC: 12eef | Get or set file attributes
2018-12-17T21:53:09.336813577Z 67 PC: 12f16 | Get or set file attributes
2018-12-17T21:53:09.348043804Z 61 PC: 13850 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:53:09.361878984Z 66 PC: 13e8c | Move file pointer
2018-12-17T21:53:09.364878519Z 66 PC: 13e9a | Move file pointer
2018-12-17T21:53:09.366598858Z 66 PC: 13ea8 | Move file pointer
2018-12-17T21:53:09.368377058Z 66 PC: 13982 | Move file pointer
2018-12-17T21:53:09.370844709Z 63 PC: 13923 | Read file or device (Read 5776 bytes on handle 5)
2018-12-17T21:53:09.378742648Z 66 PC: 13982 | Move file pointer
2018-12-17T21:53:09.380517086Z 64 PC: 13923 | Write file or device (Write 5776 bytes on handle 5)
2018-12-17T21:53:09.389124393Z 87 PC: 12f5d | Get or set file date and time
2018-12-17T21:53:09.390955894Z 62 PC: 138a0 | Close file
2018-12-17T21:53:09.398561475Z 67 PC: 12f16 | Get or set file attributes
2018-12-17T21:53:09.409298591Z 53 PC: 130fc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:09.410571359Z 37 PC: 13105 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:09.41165935Z 53 PC: 130fc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:09.413668751Z 37 PC: 13105 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:09.415134568Z 53 PC: 130fc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:09.416623719Z 37 PC: 13105 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:09.418674077Z 53 PC: 130fc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:09.419945406Z 37 PC: 13105 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:09.421363216Z 53 PC: 130fc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:09.423638527Z 37 PC: 13105 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:09.425150324Z 53 PC: 130fc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:09.426628941Z 37 PC: 13105 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:09.42885406Z 53 PC: 130fc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:09.430149723Z 37 PC: 13105 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:09.431515734Z 53 PC: 130fc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:09.433724508Z 37 PC: 13105 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:09.442404045Z 53 PC: 130fc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:09.44450122Z 37 PC: 13105 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:09.446217098Z 53 PC: 130fc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:09.447605346Z 37 PC: 13105 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:09.448774787Z 53 PC: 130fc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:09.450701558Z 37 PC: 13105 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:09.452103757Z 53 PC: 130fc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:09.453529893Z 37 PC: 13105 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:09.455207207Z 53 PC: 130fc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:09.456898509Z 37 PC: 13105 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:09.458130515Z 53 PC: 130fc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:09.459878583Z 37 PC: 13105 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:09.461376456Z 53 PC: 130fc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:09.462738372Z 37 PC: 13105 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:09.464803462Z 53 PC: 130fc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:09.466541721Z 37 PC: 13105 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:09.46787939Z 53 PC: 130fc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:09.46950563Z 37 PC: 13105 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:09.471590124Z 53 PC: 130fc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:09.473007082Z 37 PC: 13105 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:09.474368918Z 53 PC: 130fc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:09.476261356Z 37 PC: 13105 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:09.477791005Z 41 PC: 130b3 | Parse filename
2018-12-17T21:53:09.479322792Z 41 PC: 130c1 | Parse filename
2018-12-17T21:53:09.481609154Z 75 PC: 130cc | Execute program
2018-12-17T21:53:09.501483197Z 80 PC: 1e929 | Set current PSP
2018-12-17T21:53:09.502676192Z 48 PC: 1e92e | Get DOS version
2018-12-17T21:53:09.505650536Z 99 PC: 25110 | Get DBCS lead byte table pointer
2018-12-17T21:53:09.508538289Z 101 PC: 1e9b4 | Get extended country info
2018-12-17T21:53:09.51014415Z 99 PC: 1e9ba | Get DBCS lead byte table pointer
2018-12-17T21:53:09.512149821Z 74 PC: 1ea1c | Reallocate memory
2018-12-17T21:53:09.513898727Z 25 PC: 1ea53 | Get default drive
2018-12-17T21:53:09.515234416Z 37 PC: 1e513 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:53:09.517573754Z 37 PC: 1e51a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:09.519647167Z 37 PC: 1e521 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:09.524055379Z 74 PC: 1d6bc | Reallocate memory
2018-12-17T21:53:09.52663415Z 72 PC: 1d6fd | Allocate memory
2018-12-17T21:53:09.528877327Z 72 PC: 1d735 | Allocate memory
2018-12-17T21:53:09.530866298Z 72 PC: 1d73d | Allocate memory