Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Dope.5219

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:20.364556474Z 48 PC: 12a4b | Get DOS version
2018-12-17T22:21:20.366312734Z 53 PC: 12bc7 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:20.368826784Z 53 PC: 12bd4 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:21:20.370156274Z 53 PC: 12be1 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:21:20.371974999Z 53 PC: 12bee | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:21:20.37422389Z 37 PC: 12c02 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:20.37608447Z 74 PC: 12af3 | Reallocate memory
2018-12-17T22:21:20.378459772Z 68 PC: 1332b | I/O control for devices (Set for = 'WW')
2018-12-17T22:21:20.382448809Z 68 PC: 1332b | I/O control for devices (Set for = ' ')
2018-12-17T22:21:20.38589381Z 44 PC: 12d90 | Get time 0x12d90: mov al, dl
0x12d92: mov ah, 0
0x12d94: push ax
0x12d95: call 0x1338d
0x12d98: pop cx
0x12d99: mov ax, 0x3013
0x12d9c: push ax
0x12d9d: call 0x130ef
0x12da0: pop cx
0x12da1: call 0x12f79
0x12da4: push ax
0x12da5: lea ax, word ptr [bp - 0x50]
0x12da8: push ax
0x12da9: call 0x13020
0x12dac: pop cx
0x12dad: pop cx
0x12dae: cmp byte ptr [bp - 0x50], 0x5a
0x12db2: jg 0x12dc3
0x12db4: cmp byte ptr [bp - 0x50], 0x41
0x12db8: jl 0x12dc3
2018-12-17T22:21:20.38930428Z 71 PC: 13103 | Get current directory
2018-12-17T22:21:20.39498907Z 25 PC: 13107 | Get default drive
2018-12-17T22:21:20.396526951Z 64 PC: 12c8f | Write file or device (Write 14 bytes on handle 2)
2018-12-17T22:21:20.40190716Z 37 PC: 12c0e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:20.403416144Z 37 PC: 12c19 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:21:20.404908642Z 37 PC: 12c24 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:21:20.406396781Z 37 PC: 12c2f | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:21:20.407744154Z 76 PC: 12bb8 | Terminate with return code (Return code = '3')