Sample viewer

vx.netlux.org/Virus.DOS.HLLW.ArjSelf.5288

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:49.29260577Z 53 PC: 133ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:19:49.2944247Z 53 PC: 133ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:19:49.296000206Z 53 PC: 133ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:19:49.297623656Z 53 PC: 133ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:49.299870288Z 53 PC: 133ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:49.301194882Z 53 PC: 133ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:49.302973751Z 53 PC: 133ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:19:49.307664781Z 53 PC: 133ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:19:49.309028832Z 53 PC: 133ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:19:49.310439166Z 53 PC: 133ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:19:49.321754466Z 53 PC: 133ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:19:49.325121953Z 53 PC: 133ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:19:49.326446736Z 53 PC: 133ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:19:49.328325887Z 53 PC: 133ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:19:49.330252985Z 53 PC: 133ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:19:49.331867864Z 53 PC: 133ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:19:49.333547738Z 53 PC: 133ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:19:49.336117319Z 53 PC: 133ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:19:49.337810636Z 53 PC: 133ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:19:49.33944192Z 37 PC: 133cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:19:49.35367969Z 37 PC: 133d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:49.355583328Z 37 PC: 133df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:49.35753414Z 37 PC: 133e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:19:49.362648151Z 68 PC: 14112 | I/O control for devices (Set for = '�B')
2018-12-17T22:19:49.364377756Z 48 PC: 13c42 | Get DOS version
2018-12-17T22:19:49.366698606Z 67 PC: 12ec7 | Get or set file attributes
2018-12-17T22:19:49.373274881Z 67 PC: 12ec7 | Get or set file attributes
2018-12-17T22:19:49.383116934Z 64 PC: 137d8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:19:49.385238293Z 37 PC: 13511 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:19:49.387099592Z 37 PC: 13511 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:19:49.388599992Z 37 PC: 13511 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:19:49.39004251Z 37 PC: 13511 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:49.391455569Z 37 PC: 13511 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:49.392952804Z 37 PC: 13511 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:49.394406672Z 37 PC: 13511 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:19:49.395590755Z 37 PC: 13511 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:19:49.398090298Z 37 PC: 13511 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:19:49.399376406Z 37 PC: 13511 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:19:49.400582051Z 37 PC: 13511 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:19:49.405402778Z 37 PC: 13511 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:19:49.40647851Z 37 PC: 13511 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:19:49.407590245Z 37 PC: 13511 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:19:49.409396147Z 37 PC: 13511 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:19:49.410529996Z 37 PC: 13511 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:19:49.411603395Z 37 PC: 13511 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:19:49.413693744Z 37 PC: 13511 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:19:49.414744118Z 37 PC: 13511 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:19:49.415796559Z 76 PC: 13550 | Terminate with return code (Return code = '0')