Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Delami.4701

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:03.758353128Z 53 PC: 1349a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:03.760179534Z 53 PC: 1349a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:03.76150161Z 53 PC: 1349a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:03.763044269Z 53 PC: 1349a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:03.769533997Z 53 PC: 1349a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:03.771063889Z 53 PC: 1349a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:03.772666576Z 53 PC: 1349a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:03.776875344Z 53 PC: 1349a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:03.778505242Z 53 PC: 1349a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:03.779870768Z 53 PC: 1349a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:03.794267395Z 53 PC: 1349a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:03.795798763Z 53 PC: 1349a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:03.797938677Z 53 PC: 1349a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:03.799621644Z 53 PC: 1349a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:03.80152662Z 53 PC: 1349a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:03.802810586Z 53 PC: 1349a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:03.804215355Z 53 PC: 1349a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:03.806213424Z 53 PC: 1349a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:03.808001575Z 53 PC: 1349a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:03.809732662Z 37 PC: 134af | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:03.812566198Z 37 PC: 134b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:03.813712118Z 37 PC: 134bf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:03.814809198Z 37 PC: 134c7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:03.817148599Z 68 PC: 1403d | I/O control for devices (Set for = '')
2018-12-17T22:20:03.819295342Z 48 PC: 13c53 | Get DOS version
2018-12-17T22:20:03.820457617Z 44 PC: 14174 | Get time 0x14174: mov word ptr [0x3e], cx
0x14178: mov word ptr [0x40], dx
0x1417c: retf
0x1417d: call 0x141c4
0x14180: jb 0x14191
0x14182: mov cx, word ptr es:[di + 4]
0x14186: cmp cx, 1
0x14189: je 0x14191
0x1418b: xor bx, bx
0x1418d: push cs
0x1418e: call 0x23d05
0x14191: retf 4
0x14194: call 0x141c4
0x14197: jb 0x141ac
0x14199: mov ax, cx
0x1419b: mov dx, bx
0x1419d: mov cx, word ptr es:[di + 4]
0x141a1: cmp cx, 1
0x141a4: je 0x141ac
0x141a6: xor bx, bx
2018-12-17T22:20:03.822988518Z 26 PC: 1323d | Set disk transfer address
2018-12-17T22:20:03.824847853Z 78 PC: 13249 | Find first file
2018-12-17T22:20:03.829994046Z 26 PC: 13261 | Set disk transfer address
2018-12-17T22:20:03.831088471Z 79 PC: 13266 | Find next file
2018-12-17T22:20:03.833871185Z 26 PC: 1323d | Set disk transfer address
2018-12-17T22:20:03.834863686Z 78 PC: 13249 | Find first file
2018-12-17T22:20:03.841071883Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.188346672Z 61 PC: 13b05 | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:20:04.19766529Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 5)
2018-12-17T22:20:04.205948925Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.208097246Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.209711371Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.211883962Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.214746599Z 64 PC: 13bd8 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:20:04.222106566Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.238900944Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.249140352Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 6)
2018-12-17T22:20:04.260789951Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.262798424Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.273237965Z 87 PC: 1320d | Get or set file date and time
2018-12-17T22:20:04.275784185Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.284196658Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.295707674Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.298940033Z 26 PC: 13261 | Set disk transfer address
2018-12-17T22:20:04.300268817Z 79 PC: 13266 | Find next file
2018-12-17T22:20:04.304543174Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.314601284Z 61 PC: 13b05 | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T22:20:04.334601293Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 5)
2018-12-17T22:20:04.364700446Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.366687744Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.36851134Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.370355572Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.373142459Z 64 PC: 13bd8 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:20:04.380395165Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.396721297Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.405890642Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 6)
2018-12-17T22:20:04.414946456Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.417113696Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.426572619Z 87 PC: 1320d | Get or set file date and time
2018-12-17T22:20:04.429590031Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.439435042Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.451965952Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.455510697Z 26 PC: 13261 | Set disk transfer address
2018-12-17T22:20:04.457275811Z 79 PC: 13266 | Find next file
2018-12-17T22:20:04.461918058Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.475270949Z 61 PC: 13b05 | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T22:20:04.483717069Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 5)
2018-12-17T22:20:04.492162762Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.495204738Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.497618218Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.499768517Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.502954764Z 64 PC: 13bd8 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:20:04.511188322Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.522647231Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.53101386Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 6)
2018-12-17T22:20:04.540612323Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.542348666Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.550574998Z 87 PC: 1320d | Get or set file date and time
2018-12-17T22:20:04.553879796Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.562036734Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.57295216Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.57660816Z 26 PC: 13261 | Set disk transfer address
2018-12-17T22:20:04.578331258Z 79 PC: 13266 | Find next file
2018-12-17T22:20:04.582838132Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.596196885Z 61 PC: 13b05 | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T22:20:04.604738692Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 5)
2018-12-17T22:20:04.612869007Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.615628773Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.617920637Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.619873196Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.621961754Z 64 PC: 13bd8 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:20:04.630338503Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.639858669Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.647592845Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 6)
2018-12-17T22:20:04.657590171Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.659636544Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.667740759Z 87 PC: 1320d | Get or set file date and time
2018-12-17T22:20:04.670673365Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.679200712Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.689996578Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.693252538Z 26 PC: 13261 | Set disk transfer address
2018-12-17T22:20:04.695252444Z 79 PC: 13266 | Find next file
2018-12-17T22:20:04.699664199Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.711570435Z 61 PC: 13b05 | Open file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T22:20:04.72086931Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 5)
2018-12-17T22:20:04.728870277Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.731657311Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.733989176Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.735900995Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.738160177Z 64 PC: 13bd8 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:20:04.746322621Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.756004133Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.763742997Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 6)
2018-12-17T22:20:04.773301631Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.775357324Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.784294643Z 87 PC: 1320d | Get or set file date and time
2018-12-17T22:20:04.787764216Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.795909439Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.806473718Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.810019757Z 26 PC: 13261 | Set disk transfer address
2018-12-17T22:20:04.81222951Z 79 PC: 13266 | Find next file
2018-12-17T22:20:04.817126207Z 26 PC: 1323d | Set disk transfer address
2018-12-17T22:20:04.819585524Z 78 PC: 13249 | Find first file
2018-12-17T22:20:04.828375295Z 67 PC: 1319f | Get or set file attributes
2018-12-17T22:20:04.835213937Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.843765983Z 87 PC: 131e0 | Get or set file date and time
2018-12-17T22:20:04.846191879Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.848948881Z 61 PC: 13b05 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:04.85866115Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.860983276Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.863049863Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.865414629Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.867602705Z 63 PC: 13bd8 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:20:04.876225997Z 63 PC: 13bd8 | Read file or device (Read 4700 bytes on handle 5)
2018-12-17T22:20:04.885725691Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.887981516Z 64 PC: 13bd8 | Write file or device (Write 4700 bytes on handle 5)
2018-12-17T22:20:04.904493705Z 66 PC: 141de | Move file pointer
2018-12-17T22:20:04.907686481Z 66 PC: 141ec | Move file pointer
2018-12-17T22:20:04.909526066Z 66 PC: 141fa | Move file pointer
2018-12-17T22:20:04.911608957Z 66 PC: 13c37 | Move file pointer
2018-12-17T22:20:04.913678937Z 64 PC: 13b36 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:20:04.924063598Z 87 PC: 1320d | Get or set file date and time
2018-12-17T22:20:04.926378604Z 62 PC: 13b55 | Close file
2018-12-17T22:20:04.935150362Z 67 PC: 131c6 | Get or set file attributes
2018-12-17T22:20:04.942235812Z 53 PC: 13410 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:04.944106951Z 37 PC: 13419 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:04.945784899Z 53 PC: 13410 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:04.94858147Z 37 PC: 13419 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:04.950337031Z 53 PC: 13410 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:04.952149903Z 37 PC: 13419 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:04.954840893Z 53 PC: 13410 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:04.956992432Z 37 PC: 13419 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:04.958712039Z 53 PC: 13410 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:04.961263586Z 37 PC: 13419 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:04.963263956Z 53 PC: 13410 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:04.965073427Z 37 PC: 13419 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:04.967384223Z 53 PC: 13410 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:04.969762463Z 37 PC: 13419 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:04.971513515Z 53 PC: 13410 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:04.974023591Z 37 PC: 13419 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:04.976097934Z 53 PC: 13410 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:04.977877404Z 37 PC: 13419 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:04.980752536Z 53 PC: 13410 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:04.982548731Z 37 PC: 13419 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:04.984209237Z 53 PC: 13410 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:04.985911291Z 37 PC: 13419 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:04.988607002Z 53 PC: 13410 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:04.990301347Z 37 PC: 13419 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:04.991972528Z 53 PC: 13410 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:04.994657475Z 37 PC: 13419 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:04.996235691Z 53 PC: 13410 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:04.997879028Z 37 PC: 13419 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:05.000358463Z 53 PC: 13410 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:05.002018947Z 37 PC: 13419 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:05.003664475Z 53 PC: 13410 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:05.006103284Z 37 PC: 13419 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:05.007893155Z 53 PC: 13410 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:05.009696836Z 37 PC: 13419 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:05.012119071Z 53 PC: 13410 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:05.01364289Z 37 PC: 13419 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:05.015412349Z 53 PC: 13410 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:05.017605865Z 37 PC: 13419 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:05.01996713Z 41 PC: 133c7 | Parse filename
2018-12-17T22:20:05.021944736Z 41 PC: 133d5 | Parse filename
2018-12-17T22:20:05.024464432Z 75 PC: 133e0 | Execute program
2018-12-17T22:20:05.039179847Z 80 PC: 18eb9 | Set current PSP
2018-12-17T22:20:05.040182004Z 48 PC: 18ebe | Get DOS version
2018-12-17T22:20:05.042169297Z 99 PC: 1f6a0 | Get DBCS lead byte table pointer
2018-12-17T22:20:05.044272236Z 101 PC: 18f44 | Get extended country info
2018-12-17T22:20:05.045509735Z 99 PC: 18f4a | Get DBCS lead byte table pointer
2018-12-17T22:20:05.04727517Z 74 PC: 18fac | Reallocate memory
2018-12-17T22:20:05.048516973Z 25 PC: 18fe3 | Get default drive
2018-12-17T22:20:05.049822295Z 37 PC: 18aa3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:20:05.051537778Z 37 PC: 18aaa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:05.052501515Z 37 PC: 18ab1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:05.05545684Z 74 PC: 17c4c | Reallocate memory
2018-12-17T22:20:05.057317883Z 72 PC: 17c8d | Allocate memory
2018-12-17T22:20:05.05880211Z 72 PC: 17cc5 | Allocate memory
2018-12-17T22:20:05.060206616Z 72 PC: 17ccd | Allocate memory