Sample viewer

vx.netlux.org/Virus.DOS.HLLP.6800

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:23.208570664Z 53 PC: 1339a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:23.210706835Z 53 PC: 1339a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:23.211929835Z 53 PC: 1339a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:23.213120325Z 53 PC: 1339a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:23.214859111Z 53 PC: 1339a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:23.216341592Z 53 PC: 1339a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:23.217861206Z 53 PC: 1339a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:23.219866502Z 53 PC: 1339a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:23.221083362Z 53 PC: 1339a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:23.222309643Z 53 PC: 1339a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:23.224493195Z 53 PC: 1339a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:23.225692892Z 53 PC: 1339a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:23.227092174Z 53 PC: 1339a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:23.229688073Z 53 PC: 1339a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:23.231188451Z 53 PC: 1339a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:23.232763792Z 53 PC: 1339a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:23.23917378Z 53 PC: 1339a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:23.241229102Z 53 PC: 1339a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:23.243260082Z 53 PC: 1339a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:23.249510079Z 37 PC: 133af | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:23.251065291Z 37 PC: 133b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:23.2522858Z 37 PC: 133bf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:23.254553739Z 37 PC: 133c7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:23.256034139Z 68 PC: 140eb | I/O control for devices (Set for = '')
2018-12-17T21:53:23.257637232Z 48 PC: 13e11 | Get DOS version
2018-12-17T21:53:23.260395446Z 61 PC: 13cc3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:53:23.267103078Z 66 PC: 13df5 | Move file pointer
2018-12-17T21:53:23.268777765Z 63 PC: 13d96 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T21:53:23.272325026Z 62 PC: 13d13 | Close file
2018-12-17T21:53:23.274323331Z 48 PC: 13e11 | Get DOS version
2018-12-17T21:53:23.275780615Z 61 PC: 13cc3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:53:23.283110348Z 63 PC: 13d96 | Read file or device (Read 6800 bytes on handle 5)
2018-12-17T21:53:23.291264007Z 62 PC: 13d13 | Close file
2018-12-17T21:53:23.29396588Z 26 PC: 1324b | Set disk transfer address
2018-12-17T21:53:23.296527006Z 78 PC: 13257 | Find first file
2018-12-17T21:53:23.303293852Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.304849996Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.309635526Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.311570831Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.314966202Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.316926718Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.320158508Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.321569341Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.326044665Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.327615183Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.330960763Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.332985052Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.336642674Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.33785995Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.341463463Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.342840465Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.346206861Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.347823518Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.351272401Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.352266862Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.356143934Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.357089234Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.360308072Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.362231793Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.366197021Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.36715207Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.370817405Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.372663787Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.376211267Z 61 PC: 13cc3 | Open file (Filename = '\TEST.EXE')
2018-12-17T21:53:23.383332832Z 66 PC: 13df5 | Move file pointer
2018-12-17T21:53:23.385041551Z 63 PC: 13d96 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T21:53:23.387907428Z 62 PC: 13d13 | Close file
2018-12-17T21:53:23.39043953Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.391421386Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.3939105Z 26 PC: 1324b | Set disk transfer address
2018-12-17T21:53:23.395563574Z 78 PC: 13257 | Find first file
2018-12-17T21:53:23.401318054Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.402463177Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.420297807Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.421583354Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.424256516Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.426025843Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.428634306Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.430050057Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.434575239Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.43612439Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.438985266Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.441218412Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.458702513Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.460766734Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.464272346Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.466302347Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.469229697Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.471331411Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.474388122Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.475724282Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.479227598Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.480851435Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.483502939Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.484885864Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.487732161Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.489075159Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.493209003Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.494862817Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.497456815Z 26 PC: 1326f | Set disk transfer address
2018-12-17T21:53:23.499665745Z 79 PC: 13274 | Find next file
2018-12-17T21:53:23.502020429Z 48 PC: 13e11 | Get DOS version
2018-12-17T21:53:23.503348891Z 26 PC: 1324b | Set disk transfer address
2018-12-17T21:53:23.50568919Z 78 PC: 13257 | Find first file
2018-12-17T21:53:23.511763103Z 48 PC: 13e11 | Get DOS version
2018-12-17T21:53:23.513277746Z 61 PC: 13cc3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:53:23.521139479Z 66 PC: 13df5 | Move file pointer
2018-12-17T21:53:23.522706341Z 63 PC: 13d96 | Read file or device (Read 6800 bytes on handle 5)
2018-12-17T21:53:23.531164896Z 66 PC: 13df5 | Move file pointer
2018-12-17T21:53:23.534454865Z 64 PC: 13d96 | Write file or device (Write 6800 bytes on handle 5)
2018-12-17T21:53:23.549151551Z 66 PC: 13df5 | Move file pointer
2018-12-17T21:53:23.550481837Z 64 PC: 13cf4 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T21:53:23.558630242Z 87 PC: 1321b | Get or set file date and time
2018-12-17T21:53:23.560373864Z 62 PC: 13d13 | Close file
2018-12-17T21:53:23.567359877Z 48 PC: 13e11 | Get DOS version
2018-12-17T21:53:23.569548896Z 41 PC: 13303 | Parse filename
2018-12-17T21:53:23.570859264Z 41 PC: 13311 | Parse filename
2018-12-17T21:53:23.572578753Z 75 PC: 1331c | Execute program
2018-12-17T21:53:23.589456475Z 9 PC: 1bd92 | Display string (String= 'Goat file (COM). Size=0000C738h/0000051000d bytes. ')
2018-12-17T21:53:23.593528763Z 76 PC: 1bd96 | Terminate with return code (Return code = '36')
2018-12-17T21:53:23.598177357Z 64 PC: 13a1b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:53:23.600445082Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:23.601805033Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:23.603661656Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:23.6049424Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:23.61101159Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:23.613179144Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:23.614154556Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:23.615420704Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:23.61754961Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:23.618815862Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:23.620057119Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:23.622285565Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:23.623577486Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:23.624838416Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:23.62717467Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:23.628469886Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:23.629755606Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:23.632069068Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:23.633374896Z 37 PC: 134f1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:23.634655175Z 76 PC: 13530 | Terminate with return code (Return code = '0')