Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DN.8000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:57.325447535Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:57.327807878Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:57.329450734Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:57.330991958Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:57.333807019Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:57.335385995Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:57.337660632Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:57.339678423Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:57.340937615Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:57.342176219Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:57.344410755Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:57.345626485Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:57.346804118Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:57.348834147Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:57.350175506Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:57.35164607Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:57.353917256Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:57.355453329Z 53 PC: 14ab6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:57.356957474Z 37 PC: 14acb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:57.35992272Z 37 PC: 14ad3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:57.361294471Z 37 PC: 14adb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:57.362667778Z 37 PC: 14ae3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:57.365552113Z 68 PC: 15141 | I/O control for devices (Set for = '')
2018-12-17T22:20:57.463796574Z 37 PC: 14177 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:57.465036627Z 48 PC: 156b8 | Get DOS version
2018-12-17T22:20:57.466866803Z 53 PC: 1490c | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:57.46788979Z 37 PC: 14928 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:57.468830299Z 53 PC: 1490c | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:20:57.47048603Z 37 PC: 14928 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:20:57.471666687Z 53 PC: 1490c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:57.472702467Z 37 PC: 14928 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:57.475406649Z 51 PC: 147fb | Get or set Ctrl-Break
2018-12-17T22:20:57.476876663Z 60 PC: 15504 | Create or truncate file
2018-12-17T22:20:57.736990062Z 65 PC: 1564d | Delete file (Filename = '\�')
2018-12-17T22:20:57.757802217Z 48 PC: 156b8 | Get DOS version
2018-12-17T22:20:57.759733021Z 61 PC: 15504 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:57.767144443Z 66 PC: 15636 | Move file pointer
2018-12-17T22:20:57.770063557Z 63 PC: 155d7 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:20:57.777615744Z 62 PC: 15554 | Close file
2018-12-17T22:20:57.785225394Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:57.787170531Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:57.788327912Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:57.789485135Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:57.791302461Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:57.792467843Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:57.79361527Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:57.794946547Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:57.796826326Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:57.797943373Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:57.799015349Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:57.800918003Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:57.802001364Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:57.803087339Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:57.805159943Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:57.806226128Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:57.807290875Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:57.80941122Z 37 PC: 14bc5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:57.81045278Z 76 PC: 14c04 | Terminate with return code (Return code = '8')