Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Behi.14896

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:36.176718804Z 53 PC: 150aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:36.178466896Z 53 PC: 150aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:36.179845759Z 53 PC: 150aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:36.18086646Z 53 PC: 150aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:36.182184834Z 53 PC: 150aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:36.183896613Z 53 PC: 150aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:36.185034344Z 53 PC: 150aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:36.18603617Z 53 PC: 150aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:36.18786575Z 53 PC: 150aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:36.189510499Z 53 PC: 150aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:36.191089488Z 53 PC: 150aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:36.20151845Z 53 PC: 150aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:36.202827683Z 53 PC: 150aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:36.204083789Z 53 PC: 150aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:36.205870318Z 53 PC: 150aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:36.206972404Z 53 PC: 150aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:36.20802623Z 53 PC: 150aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:36.21031762Z 53 PC: 150aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:36.21173129Z 53 PC: 150aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:36.213000837Z 37 PC: 150bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:36.215099455Z 37 PC: 150c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:36.216668194Z 37 PC: 150cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:36.218096697Z 37 PC: 150d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:36.225761501Z 68 PC: 15ced | I/O control for devices (Set for = '�P.��2��� �t�.nXô,�!���.�1�.�3��,��L!ø')
2018-12-17T22:24:36.374485884Z 37 PC: 148a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:36.376506653Z 67 PC: 14ec8 | Get or set file attributes
2018-12-17T22:24:36.382773428Z 67 PC: 14ec8 | Get or set file attributes
2018-12-17T22:24:36.387055951Z 67 PC: 14ec8 | Get or set file attributes
2018-12-17T22:24:36.392311146Z 67 PC: 14ec8 | Get or set file attributes
2018-12-17T22:24:36.396847297Z 67 PC: 14ec8 | Get or set file attributes
2018-12-17T22:24:36.402387286Z 67 PC: 14ec8 | Get or set file attributes
2018-12-17T22:24:36.406618208Z 57 PC: 15a86 | Create subdirectory
2018-12-17T22:24:36.762579943Z 60 PC: 15cd1 | Create or truncate file
2018-12-17T22:24:36.776114311Z 68 PC: 15ced | I/O control for devices (Set for = '�P.��2��� �t�.nXô,�!���.�1�.�3��,��L!ø')
2018-12-17T22:24:36.779779238Z 64 PC: 154a3 | Write file or device (Write 63 bytes on handle 5)
2018-12-17T22:24:36.785310321Z 62 PC: 154e2 | Close file
2018-12-17T22:24:36.795187293Z 53 PC: 1501d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:36.797794288Z 37 PC: 15026 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:36.79962235Z 53 PC: 1501d | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:36.803014117Z 37 PC: 15026 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:36.80468623Z 53 PC: 1501d | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:36.806878899Z 37 PC: 15026 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:36.809907921Z 53 PC: 1501d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:36.811301462Z 37 PC: 15026 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:36.81296812Z 53 PC: 1501d | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:36.81544304Z 37 PC: 15026 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:36.816967485Z 53 PC: 1501d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:36.819113943Z 37 PC: 15026 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:36.821348694Z 53 PC: 1501d | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:36.822944024Z 37 PC: 15026 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:36.824654448Z 53 PC: 1501d | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:36.827787621Z 37 PC: 15026 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:36.829134671Z 53 PC: 1501d | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:36.831024936Z 37 PC: 15026 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:36.833492218Z 53 PC: 1501d | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:36.846513274Z 37 PC: 15026 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:36.848042935Z 53 PC: 1501d | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:36.850345457Z 37 PC: 15026 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:36.851775126Z 53 PC: 1501d | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:36.85325911Z 37 PC: 15026 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:36.855362676Z 53 PC: 1501d | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:36.857240495Z 37 PC: 15026 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:36.85867289Z 53 PC: 1501d | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:36.860976978Z 37 PC: 15026 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:36.862444151Z 53 PC: 1501d | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:36.863910002Z 37 PC: 15026 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:36.866559206Z 53 PC: 1501d | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:36.868962327Z 37 PC: 15026 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:36.870462068Z 53 PC: 1501d | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:36.872707682Z 37 PC: 15026 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:36.874245627Z 53 PC: 1501d | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:36.8757514Z 37 PC: 15026 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:36.878078081Z 53 PC: 1501d | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:36.880770555Z 37 PC: 15026 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:36.882859007Z 41 PC: 14fd4 | Parse filename
2018-12-17T22:24:36.88544624Z 41 PC: 14fe2 | Parse filename
2018-12-17T22:24:36.887217059Z 75 PC: 14fed | Execute program
2018-12-17T22:24:36.904056706Z 80 PC: 1a959 | Set current PSP
2018-12-17T22:24:36.905979019Z 48 PC: 1a95e | Get DOS version
2018-12-17T22:24:36.907863721Z 99 PC: 21140 | Get DBCS lead byte table pointer
2018-12-17T22:24:36.911472868Z 101 PC: 1a9e4 | Get extended country info
2018-12-17T22:24:36.91428589Z 99 PC: 1a9ea | Get DBCS lead byte table pointer
2018-12-17T22:24:36.915776816Z 74 PC: 1aa4c | Reallocate memory
2018-12-17T22:24:36.917954571Z 25 PC: 1aa83 | Get default drive
2018-12-17T22:24:36.920315239Z 37 PC: 1a543 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:24:36.921731169Z 37 PC: 1a54a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:36.923015791Z 37 PC: 1a551 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:36.928572879Z 74 PC: 196ec | Reallocate memory
2018-12-17T22:24:36.930334294Z 72 PC: 1972d | Allocate memory
2018-12-17T22:24:36.932197438Z 72 PC: 19765 | Allocate memory
2018-12-17T22:24:36.935300725Z 72 PC: 1976d | Allocate memory