Sample viewer

vx.netlux.org/Virus.DOS.HLLP.ASEA.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:15.799406901Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:15.801766549Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:15.803338026Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:15.804893054Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:15.806660617Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:15.808119811Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:15.809484931Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:15.810853605Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:15.81222432Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:15.813442078Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:15.814903772Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:15.817632516Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:15.819285454Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:15.820910652Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:15.823021599Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:15.824380316Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:15.825749095Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:15.831992289Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:15.833686724Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:15.852186938Z 37 PC: 13d4f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:15.854268233Z 37 PC: 13d57 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:15.856216735Z 37 PC: 13d5f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:15.857956279Z 37 PC: 13d67 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:15.860698633Z 68 PC: 14cf5 | I/O control for devices (Set for = '0>s')
2018-12-17T22:24:15.862635179Z 53 PC: 13841 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:24:15.864158432Z 37 PC: 1385d | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:24:15.866144578Z 44 PC: 14e2c | Get time 0x14e2c: mov word ptr [0x76], cx
0x14e30: mov word ptr [0x78], dx
0x14e34: retf
0x14e35: mov cx, di
0x14e37: mov si, 0xa
0x14e3a: mov bx, dx
0x14e3c: or bx, bx
0x14e3e: jns 0x14e51
0x14e40: neg bx
0x14e42: neg ax
0x14e44: sbb bx, 0
0x14e47: call 0x14e51
0x14e4a: dec di
0x14e4b: mov byte ptr es:[di], 0x2d
0x14e4f: inc cx
0x14e50: ret
0x14e51: xor dx, dx
0x14e53: xchg ax, bx
0x14e54: div si
0x14e56: xchg ax, bx
2018-12-17T22:24:15.868936253Z 48 PC: 14825 | Get DOS version
2018-12-17T22:24:15.870858877Z 61 PC: 14663 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:24:15.878658892Z 66 PC: 14ff5 | Move file pointer
2018-12-17T22:24:15.881813098Z 66 PC: 15003 | Move file pointer
2018-12-17T22:24:15.883526079Z 66 PC: 15011 | Move file pointer
2018-12-17T22:24:15.885620544Z 63 PC: 14736 | Read file or device (Read 15037 bytes on handle 5)
2018-12-17T22:24:15.895847869Z 62 PC: 146b3 | Close file
2018-12-17T22:24:15.897947832Z 48 PC: 14825 | Get DOS version
2018-12-17T22:24:15.9005716Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.907908034Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.919608339Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.926353325Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.934580689Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.941406308Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.949052265Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.956774496Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.964812345Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.972333943Z 67 PC: 13817 | Get or set file attributes
2018-12-17T22:24:15.982296702Z 64 PC: 143bb | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:24:15.984204145Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:15.985722577Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:15.987159191Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:15.989445865Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:15.990560241Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:15.991626725Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:15.993366499Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:15.994438859Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:15.995618513Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:15.997434203Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:15.998802564Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:16.000232694Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:16.002552857Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:16.004364569Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:16.006145274Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:16.008374815Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:16.010105779Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:16.011788291Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:16.01398893Z 37 PC: 13e91 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:16.015607441Z 76 PC: 13ed0 | Terminate with return code (Return code = '0')