Sample viewer

vx.netlux.org/Virus.DOS.HLLW.Worf.5872

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:50:40.617474508Z 53 PC: 1318a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:50:40.627277932Z 53 PC: 1318a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:50:40.628465125Z 53 PC: 1318a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:50:40.629841873Z 53 PC: 1318a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:50:40.631554745Z 53 PC: 1318a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:50:40.632837571Z 53 PC: 1318a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:40.633954505Z 53 PC: 1318a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:50:40.63529931Z 53 PC: 1318a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:50:40.636768437Z 53 PC: 1318a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:50:40.638654755Z 53 PC: 1318a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:50:40.640482226Z 53 PC: 1318a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:50:40.647144905Z 53 PC: 1318a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:50:40.648460774Z 53 PC: 1318a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:50:40.649817159Z 53 PC: 1318a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:50:40.652021139Z 53 PC: 1318a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:50:40.654087861Z 53 PC: 1318a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:50:40.656105993Z 53 PC: 1318a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:50:40.66617623Z 53 PC: 1318a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:50:40.667424564Z 53 PC: 1318a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:50:40.668526791Z 37 PC: 1319f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:50:40.670314144Z 37 PC: 131a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:50:40.671561991Z 37 PC: 131af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:40.673075713Z 37 PC: 131b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:50:40.675533286Z 68 PC: 13da1 | I/O control for devices (Set for = 'Lr')
2018-12-17T21:50:40.677382784Z 44 PC: 13ed8 | Get time 0x13ed8: mov word ptr [0x3e], cx
0x13edc: mov word ptr [0x40], dx
0x13ee0: retf
0x13ee1: call 0x13f28
0x13ee4: jb 0x13ef5
0x13ee6: mov cx, word ptr es:[di + 4]
0x13eea: cmp cx, 1
0x13eed: je 0x13ef5
0x13eef: xor bx, bx
0x13ef1: push cs
0x13ef2: call 0x23a69
0x13ef5: retf 4
0x13ef8: call 0x13f28
0x13efb: jb 0x13f10
0x13efd: mov ax, cx
0x13eff: mov dx, bx
0x13f01: mov cx, word ptr es:[di + 4]
0x13f05: cmp cx, 1
0x13f08: je 0x13f10
0x13f0a: xor bx, bx
2018-12-17T21:50:40.679033341Z 26 PC: 12fc7 | Set disk transfer address
2018-12-17T21:50:40.680393271Z 78 PC: 12fd3 | Find first file
2018-12-17T21:50:40.684532636Z 26 PC: 12fc7 | Set disk transfer address
2018-12-17T21:50:40.685463173Z 78 PC: 12fd3 | Find first file
2018-12-17T21:50:40.692814276Z 64 PC: 1354d | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:50:40.695521588Z 64 PC: 1354d | Write file or device (Write 16 bytes on handle 1)
2018-12-17T21:50:40.699165685Z 64 PC: 1354d | Write file or device (Write 19 bytes on handle 1)
2018-12-17T21:50:40.718244887Z 64 PC: 1354d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:50:40.719700376Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:50:40.720673868Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:50:40.723261341Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:50:40.724238614Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:50:40.725067376Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:50:40.726136987Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:50:40.727198145Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:50:40.727962973Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:50:40.729298512Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:50:40.730484524Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:50:40.731247012Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:50:40.732144866Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:50:40.745713247Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:50:40.747359471Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:50:40.74877591Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:50:40.749894768Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:50:40.750870724Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:50:40.752271927Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:50:40.753413938Z 37 PC: 132e1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:50:40.75436353Z 76 PC: 13320 | Terminate with return code (Return code = '0')