Sample viewer

vx.netlux.org/Virus.DOS.Lemming.2144.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:20.739572614Z 255 PC: 12a66 | UNKNOWN!
2018-12-17T22:19:20.741258832Z 82 PC: 12b59 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:19:20.742333945Z 88 PC: 12a91 | case 0xGet or set allocation strateg:
2018-12-17T22:19:20.743351877Z 88 PC: 12a9b | case 0xGet or set allocation strateg:
2018-12-17T22:19:20.745077536Z 53 PC: 130dc | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:19:20.746152037Z 37 PC: 130e9 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:19:20.74738126Z 53 PC: 1310f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:19:20.748639681Z 37 PC: 1311f | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:19:20.750742919Z 76 PC: 12a46 | Terminate with return code (Return code = '0')
2018-12-17T22:19:20.753968291Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:19:20.755367083Z 72 PC: 12174 | Allocate memory
2018-12-17T22:19:20.757578851Z 72 PC: 1218d | Allocate memory
2018-12-17T22:19:20.75966089Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:20.76063484Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:20.770186598Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.771377587Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.77254633Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.779898813Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.781137608Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.782534826Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.783997472Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.785274758Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.786125601Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.787999024Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.789767578Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.79149754Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.79348461Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.795349273Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.796708198Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.799664285Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.800986359Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.802761639Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.804103965Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.806688408Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.807858Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.809454046Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.810945308Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.81263947Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.813807676Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.816028793Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.817531049Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.819625415Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.821594733Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.82339896Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.824556972Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.831444359Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.832683835Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.834406071Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.836009255Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.838101087Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.83944409Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.842042029Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.843412911Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.845366382Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.847285373Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.84891959Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.850107984Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.852124781Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.853148402Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.854538654Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.86409609Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.866049011Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.867464256Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.877201582Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.878298588Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.8799104Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.883364071Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.884818324Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.885899425Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.888034044Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.889315504Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.891013487Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.892943378Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.894770407Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:20.895878821Z 62 PC: 122ab | Close file
2018-12-17T22:19:20.899009172Z 99 PC: 994f7 | Get DBCS lead byte table pointer
2018-12-17T22:19:20.900466902Z 56 PC: 93d19 | Get or set country info
2018-12-17T22:19:20.902207121Z 64 PC: 99768 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:19:20.909291001Z 25 PC: 93d82 | Get default drive
2018-12-17T22:19:20.910803419Z 71 PC: 95ffd | Get current directory
2018-12-17T22:19:20.914710407Z 64 PC: 99768 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:19:20.91821269Z 2 PC: 95fd2 | Character output (Char = '3e')
2018-12-17T22:19:20.920490621Z 93 PC: 93e40 | File sharing functions
2018-12-17T22:19:20.921977966Z 93 PC: 93e47 | File sharing functions
2018-12-17T22:19:20.923811659Z 10 PC: 93e59 | Buffered keyboard input
2018-12-17T22:19:35.736360117Z 0 PC: 0 | Program terminate
2018-12-17T22:19:37.09201146Z 0 PC: 0 | Program terminate
2018-12-17T22:19:37.194678738Z 64 PC: 99768 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:19:37.201559967Z 41 PC: 93ece | Parse filename
2018-12-17T22:19:37.20450913Z 41 PC: 93f4f | Parse filename
2018-12-17T22:19:37.207848483Z 41 PC: 93f6c | Parse filename
2018-12-17T22:19:37.210335858Z 26 PC: 97417 | Set disk transfer address
2018-12-17T22:19:37.213058671Z 71 PC: 97613 | Get current directory
2018-12-17T22:19:37.221301812Z 78 PC: 9ee59 | Find first file
2018-12-17T22:19:37.230812415Z 47 PC: 9ee68 | Get disk transfer address
2018-12-17T22:19:37.233746313Z 71 PC: 9748c | Get current directory
2018-12-17T22:19:37.237254773Z 73 PC: 96b29 | Release memory
2018-12-17T22:19:37.239070544Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.24045347Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.244467082Z 61 PC: 9f177 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:19:37.251724941Z 87 PC: 9f177 | Get or set file date and time
2018-12-17T22:19:37.25340461Z 66 PC: 9f177 | Move file pointer
2018-12-17T22:19:37.255501468Z 63 PC: 9f177 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:19:37.262055086Z 66 PC: 9f177 | Move file pointer
2018-12-17T22:19:37.265203502Z 64 PC: 9f177 | Write file or device (Write 2144 bytes on handle 5)
2018-12-17T22:19:37.2802908Z 66 PC: 9f177 | Move file pointer
2018-12-17T22:19:37.282128745Z 64 PC: 9f177 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:19:37.291434591Z 87 PC: 9f177 | Get or set file date and time
2018-12-17T22:19:37.294444139Z 62 PC: 9f177 | Close file
2018-12-17T22:19:37.314562722Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.316054804Z 75 PC: 11821 | Execute program
2018-12-17T22:19:37.329447076Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:19:37.334272128Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:19:37.339949443Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:19:37.341974955Z 72 PC: 12174 | Allocate memory
2018-12-17T22:19:37.343993776Z 72 PC: 1218d | Allocate memory
2018-12-17T22:19:37.345989977Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:37.348204075Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:37.349705935Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.351265139Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.353628334Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.355660932Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.357036164Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.367148508Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.371279086Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.373430625Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.375898895Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.377789689Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.379277788Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.382038251Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.399255913Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.401310286Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.403847896Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.405933564Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.40736216Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.410169563Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.412533311Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.417751109Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.420005161Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.422215343Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.423663484Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.42648945Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.428208389Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.430126192Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.432306372Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.434664642Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.436087059Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.438155579Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.440945175Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.442990964Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.444404126Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.447242043Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.448663814Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.450720203Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.453121445Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.455459417Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.45691564Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.461610562Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.463062449Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.464944054Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.466911434Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.469614508Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.471000091Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.473439289Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.474716331Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.476712506Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.478752893Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.481409121Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.483162105Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.486043059Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.487167296Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.488764921Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.49104038Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.493364003Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.494727943Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.49733966Z 53 PC: 9f177 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.499035216Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.501032357Z 37 PC: 9f177 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:37.503130101Z 62 PC: 122ab | Close file
2018-12-17T22:19:37.506586903Z 99 PC: 994f7 | Get DBCS lead byte table pointer
2018-12-17T22:19:37.508161272Z 56 PC: 93d19 | Get or set country info
2018-12-17T22:19:37.511124145Z 64 PC: 99768 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:19:37.516051234Z 25 PC: 93d82 | Get default drive
2018-12-17T22:19:37.517735055Z 71 PC: 95ffd | Get current directory
2018-12-17T22:19:37.522531819Z 64 PC: 99768 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:19:37.526248397Z 2 PC: 95fd2 | Character output (Char = '3e')
2018-12-17T22:19:37.5286614Z 93 PC: 93e40 | File sharing functions
2018-12-17T22:19:37.530998177Z 93 PC: 93e47 | File sharing functions
2018-12-17T22:19:37.5330482Z 10 PC: 93e59 | Buffered keyboard input