Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Mud.7336

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:23.899042324Z 53 PC: 141ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:22:23.901055525Z 53 PC: 141ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:22:23.902550968Z 53 PC: 141ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:22:23.903967569Z 53 PC: 141ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:22:23.905649827Z 53 PC: 141ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:22:23.907754605Z 53 PC: 141ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:23.910273372Z 53 PC: 141ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:22:23.912149201Z 53 PC: 141ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:22:23.914679405Z 53 PC: 141ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:22:23.91668693Z 53 PC: 141ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:22:23.918714964Z 53 PC: 141ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:22:23.92088037Z 53 PC: 141ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:22:23.931152754Z 53 PC: 141ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:22:23.932634933Z 53 PC: 141ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:22:23.934608659Z 53 PC: 141ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:22:23.936076839Z 53 PC: 141ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:22:23.937517137Z 53 PC: 141ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:22:23.93962399Z 53 PC: 141ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:22:23.941406012Z 53 PC: 141ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:22:23.942966269Z 37 PC: 141df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:22:23.944834502Z 37 PC: 141e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:22:23.946588576Z 37 PC: 141ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:23.947992912Z 37 PC: 141f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:22:23.95089872Z 68 PC: 14f6c | I/O control for devices (Set for = 'V< t<=uÀ< u^tMS')
2018-12-17T22:22:24.112300426Z 37 PC: 13bf1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:22:24.114443763Z 26 PC: 1387d | Set disk transfer address
2018-12-17T22:22:24.116051751Z 78 PC: 13889 | Find first file
2018-12-17T22:22:24.123912931Z 61 PC: 148da | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:22:24.13198434Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.134218356Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.137650772Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.140013595Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.143322818Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.146256586Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.150526146Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.151954636Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.156327745Z 61 PC: 148da | Open file (Filename = 'PRINT.COM')
2018-12-17T22:22:24.164701258Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.16646486Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.174371225Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.176839254Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.180320422Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.182226432Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.194084617Z 61 PC: 148da | Open file (Filename = 'HELLO.COM')
2018-12-17T22:22:24.202608588Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.204779534Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.208125495Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.210505574Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.214345046Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.21721385Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.221078097Z 61 PC: 148da | Open file (Filename = 'PHANG.COM')
2018-12-17T22:22:24.258043646Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.260915932Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.263275101Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.265651555Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.269645056Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.271563265Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.275488474Z 61 PC: 148da | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:22:24.284048508Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.286855632Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.289174119Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.291533128Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.296111229Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.297977656Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.302871154Z 61 PC: 148da | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:22:24.311052021Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.313114465Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.31522103Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.318222104Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.32258316Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.324198323Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.328847161Z 61 PC: 148da | Open file (Filename = 'PAH.COM')
2018-12-17T22:22:24.337358667Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.33932919Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.341494453Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.344462587Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.34749558Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.349103126Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.353393475Z 61 PC: 148da | Open file (Filename = 'TEST.EXE')
2018-12-17T22:22:24.361042568Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.362909014Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.365544528Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.367519673Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.370437144Z 26 PC: 138a1 | Set disk transfer address
2018-12-17T22:22:24.372534554Z 79 PC: 138a6 | Find next file
2018-12-17T22:22:24.375687725Z 48 PC: 14a9c | Get DOS version
2018-12-17T22:22:24.37832019Z 48 PC: 14a9c | Get DOS version
2018-12-17T22:22:24.385318074Z 67 PC: 137df | Get or set file attributes
2018-12-17T22:22:24.392209435Z 67 PC: 13806 | Get or set file attributes
2018-12-17T22:22:24.411398194Z 61 PC: 148da | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:22:24.423000242Z 87 PC: 13820 | Get or set file date and time
2018-12-17T22:22:24.426057441Z 60 PC: 148da | Create or truncate file
2018-12-17T22:22:24.440418247Z 63 PC: 149ad | Read file or device (Read 7335 bytes on handle 5)
2018-12-17T22:22:24.450640927Z 64 PC: 149ad | Write file or device (Write 7335 bytes on handle 6)
2018-12-17T22:22:24.462728073Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.465051594Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.472143038Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.474569185Z 66 PC: 14a0c | Move file pointer
2018-12-17T22:22:24.476833517Z 63 PC: 149ad | Read file or device (Read 7335 bytes on handle 5)
2018-12-17T22:22:24.487079669Z 66 PC: 14a0c | Move file pointer
2018-12-17T22:22:24.489563654Z 64 PC: 149ad | Write file or device (Write 7335 bytes on handle 5)
2018-12-17T22:22:24.499107948Z 66 PC: 1506b | Move file pointer
2018-12-17T22:22:24.50117717Z 66 PC: 15079 | Move file pointer
2018-12-17T22:22:24.50365147Z 66 PC: 15087 | Move file pointer
2018-12-17T22:22:24.505819005Z 66 PC: 14a0c | Move file pointer
2018-12-17T22:22:24.507938053Z 64 PC: 1490b | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:22:24.518450781Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.526986129Z 62 PC: 1492a | Close file
2018-12-17T22:22:24.535556181Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:22:24.53812805Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:22:24.540140737Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:22:24.542700266Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:22:24.545136857Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:22:24.547179467Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:22:24.548863343Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:22:24.550795181Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:22:24.553291315Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:22:24.555005373Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:22:24.556684065Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:24.559474268Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:24.561153189Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:22:24.562877732Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:22:24.565573476Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:22:24.567085316Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:22:24.568805425Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:22:24.571322955Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:22:24.573388253Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:22:24.575108155Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:22:24.576975312Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:22:24.579380167Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:22:24.58073476Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:22:24.582105371Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:22:24.584083182Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:22:24.585437216Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:22:24.586756889Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:22:24.589191174Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:22:24.590526941Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:22:24.592193373Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:22:24.594696064Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:22:24.596070111Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:22:24.597395937Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:22:24.600140942Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:22:24.601467945Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:22:24.602851931Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:22:24.605012599Z 53 PC: 13b19 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:22:24.606398353Z 37 PC: 13b22 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:22:24.607763479Z 48 PC: 14a9c | Get DOS version
2018-12-17T22:22:24.610457672Z 41 PC: 13ad0 | Parse filename
2018-12-17T22:22:24.612403096Z 41 PC: 13ade | Parse filename
2018-12-17T22:22:24.614380064Z 75 PC: 13ae9 | Execute program