Sample viewer

vx.netlux.org/Virus.DOS.Lemming.2160

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:21.582548544Z 255 PC: 12a96 | UNKNOWN!
2018-12-17T22:24:21.584089243Z 82 PC: 12b89 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:24:21.590458134Z 88 PC: 12ac1 | case 0xGet or set allocation strateg:
2018-12-17T22:24:21.592225468Z 88 PC: 12acb | case 0xGet or set allocation strateg:
2018-12-17T22:24:21.594351564Z 53 PC: 1311c | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:24:21.596481065Z 37 PC: 13129 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:24:21.597967537Z 53 PC: 1314f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:24:21.599423121Z 37 PC: 1315f | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:24:21.601731808Z 9 PC: 12a47 | Display string (String= 'Lemming version .99 beta sample ')
2018-12-17T22:24:21.618742815Z 76 PC: 12a4c | Terminate with return code (Return code = '0')
2018-12-17T22:24:21.622560333Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:24:21.625037498Z 72 PC: 12174 | Allocate memory
2018-12-17T22:24:21.627466764Z 72 PC: 1218d | Allocate memory
2018-12-17T22:24:21.630086548Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:24:21.631559253Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:21.633268639Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.634825114Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.636538464Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.6394197Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.640748325Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.643340337Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.645265139Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.648341012Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.650480203Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.652554256Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.655222213Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.662332791Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.664121414Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.666790555Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.668349629Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.670772199Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.674832226Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.677052733Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.67873089Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.696510506Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.698297512Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.700516334Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.70297887Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.705414792Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.707132629Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.709889356Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.714462519Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.726403188Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.727877485Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.730452545Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.731953489Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.734148246Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.736408819Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.738571461Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.740300339Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.743643362Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.74512991Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.760658068Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.763033335Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.765522454Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.766947792Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.769703116Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.771177739Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.773263677Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.774859806Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.778175988Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.779933452Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.782392045Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.794423253Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.796252055Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.797577436Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.800125613Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.801743509Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.803567193Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.805388535Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.807515402Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.809130303Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.81197986Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.813988476Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.816307099Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:21.817916794Z 62 PC: 122ab | Close file
2018-12-17T22:24:21.822599291Z 99 PC: 994d7 | Get DBCS lead byte table pointer
2018-12-17T22:24:21.824449374Z 56 PC: 93cf9 | Get or set country info
2018-12-17T22:24:21.82749156Z 64 PC: 99748 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:21.833463925Z 25 PC: 93d62 | Get default drive
2018-12-17T22:24:21.835654009Z 71 PC: 95fdd | Get current directory
2018-12-17T22:24:21.840383531Z 64 PC: 99748 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:24:21.84599827Z 2 PC: 95fb2 | Character output (Char = '3e')
2018-12-17T22:24:21.849124529Z 93 PC: 93e20 | File sharing functions
2018-12-17T22:24:21.851420519Z 93 PC: 93e27 | File sharing functions
2018-12-17T22:24:21.854187717Z 10 PC: 93e39 | Buffered keyboard input
2018-12-17T22:24:36.534084251Z 0 PC: 0 | Program terminate
2018-12-17T22:24:37.889023488Z 0 PC: 0 | Program terminate
2018-12-17T22:24:37.992086451Z 64 PC: 99748 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:37.999575523Z 41 PC: 93eae | Parse filename
2018-12-17T22:24:38.003833382Z 41 PC: 93f2f | Parse filename
2018-12-17T22:24:38.009017024Z 41 PC: 93f4c | Parse filename
2018-12-17T22:24:38.011720726Z 26 PC: 973f7 | Set disk transfer address
2018-12-17T22:24:38.014513035Z 71 PC: 975f3 | Get current directory
2018-12-17T22:24:38.023248613Z 78 PC: 9ee49 | Find first file
2018-12-17T22:24:38.040753231Z 47 PC: 9ee58 | Get disk transfer address
2018-12-17T22:24:38.043329126Z 71 PC: 9746c | Get current directory
2018-12-17T22:24:38.047124679Z 73 PC: 96b09 | Release memory
2018-12-17T22:24:38.049597357Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.051733453Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.053308681Z 61 PC: 9f167 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:24:38.061560079Z 87 PC: 9f167 | Get or set file date and time
2018-12-17T22:24:38.065428254Z 66 PC: 9f167 | Move file pointer
2018-12-17T22:24:38.0673875Z 63 PC: 9f167 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:24:38.07519366Z 66 PC: 9f167 | Move file pointer
2018-12-17T22:24:38.078965895Z 64 PC: 9f167 | Write file or device (Write 2160 bytes on handle 5)
2018-12-17T22:24:38.095203634Z 66 PC: 9f167 | Move file pointer
2018-12-17T22:24:38.097606098Z 64 PC: 9f167 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:24:38.108736648Z 87 PC: 9f167 | Get or set file date and time
2018-12-17T22:24:38.111785108Z 62 PC: 9f167 | Close file
2018-12-17T22:24:38.122029423Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.123535978Z 75 PC: 11821 | Execute program
2018-12-17T22:24:38.144645533Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:24:38.150836647Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:24:38.154494316Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:24:38.156869599Z 72 PC: 12174 | Allocate memory
2018-12-17T22:24:38.159665912Z 72 PC: 1218d | Allocate memory
2018-12-17T22:24:38.162204247Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:24:38.164825197Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:38.166890389Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.169133143Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.17145353Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.174669392Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.177018706Z 62 PC: 122ab | Close file
2018-12-17T22:24:38.179549167Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.182943253Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.189929109Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.191722855Z 62 PC: 122ab | Close file
2018-12-17T22:24:38.194576911Z 53 PC: 9f167 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.196433157Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.200270811Z 37 PC: 9f167 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:38.2031325Z 62 PC: 122b1 | Close file
2018-12-17T22:24:38.206621607Z 99 PC: 994d7 | Get DBCS lead byte table pointer
2018-12-17T22:24:38.208244023Z 56 PC: 93cf9 | Get or set country info
2018-12-17T22:24:38.211835713Z 64 PC: 99748 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:38.222131923Z 25 PC: 93d62 | Get default drive
2018-12-17T22:24:38.224064121Z 71 PC: 95fdd | Get current directory
2018-12-17T22:24:38.2290389Z 64 PC: 99748 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:24:38.232754214Z 2 PC: 95fb2 | Character output (Char = '3e')
2018-12-17T22:24:38.235617507Z 93 PC: 93e20 | File sharing functions
2018-12-17T22:24:38.238957805Z 93 PC: 93e27 | File sharing functions
2018-12-17T22:24:38.241531738Z 10 PC: 93e39 | Buffered keyboard input