Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Ache.4921

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:30.678124668Z 53 PC: 1334a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:30.679508215Z 53 PC: 1334a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:26:30.681724431Z 53 PC: 1334a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:26:30.683063004Z 53 PC: 1334a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:30.684278994Z 53 PC: 1334a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:30.686621675Z 53 PC: 1334a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:30.688300914Z 53 PC: 1334a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:26:30.689944366Z 53 PC: 1334a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:26:30.692018253Z 53 PC: 1334a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:26:30.693242601Z 53 PC: 1334a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:26:30.694431103Z 53 PC: 1334a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:26:30.696148539Z 53 PC: 1334a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:26:30.698138166Z 53 PC: 1334a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:26:30.699194224Z 53 PC: 1334a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:26:30.700659993Z 53 PC: 1334a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:26:30.702181068Z 53 PC: 1334a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:26:30.703783586Z 53 PC: 1334a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:26:30.706348344Z 53 PC: 1334a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:30.707937125Z 53 PC: 1334a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:26:30.709404509Z 37 PC: 1335f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:30.710932574Z 37 PC: 13367 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:30.713133547Z 37 PC: 1336f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:30.714250777Z 37 PC: 13377 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:30.71574741Z 68 PC: 13fbc | I/O control for devices (Set for = '')
2018-12-17T22:26:30.719396611Z 44 PC: 140f3 | Get time 0x140f3: mov word ptr [0x40], cx
0x140f7: mov word ptr [0x42], dx
0x140fb: retf
0x140fc: call 0x14143
0x140ff: jb 0x14110
0x14101: mov cx, word ptr es:[di + 4]
0x14105: cmp cx, 1
0x14108: je 0x14110
0x1410a: xor bx, bx
0x1410c: push cs
0x1410d: call 0x23c84
0x14110: retf 4
0x14113: call 0x14143
0x14116: jb 0x1412b
0x14118: mov ax, cx
0x1411a: mov dx, bx
0x1411c: mov cx, word ptr es:[di + 4]
0x14120: cmp cx, 1
0x14123: je 0x1412b
0x14125: xor bx, bx
2018-12-17T22:26:30.722625083Z 48 PC: 13bd2 | Get DOS version
2018-12-17T22:26:30.724762267Z 67 PC: 12fdf | Get or set file attributes
2018-12-17T22:26:30.731820274Z 67 PC: 13006 | Get or set file attributes
2018-12-17T22:26:30.750143034Z 61 PC: 13a10 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:26:30.758916128Z 26 PC: 1307d | Set disk transfer address
2018-12-17T22:26:30.761631396Z 78 PC: 13089 | Find first file
2018-12-17T22:26:30.768369439Z 25 PC: 1317f | Get default drive
2018-12-17T22:26:30.769399343Z 71 PC: 1319e | Get current directory
2018-12-17T22:26:30.773185553Z 26 PC: 130a1 | Set disk transfer address
2018-12-17T22:26:30.774657328Z 79 PC: 130a6 | Find next file
2018-12-17T22:26:30.778155493Z 66 PC: 1415d | Move file pointer
2018-12-17T22:26:30.77990546Z 66 PC: 1416b | Move file pointer
2018-12-17T22:26:30.781797409Z 66 PC: 14179 | Move file pointer
2018-12-17T22:26:30.783584168Z 62 PC: 13a60 | Close file
2018-12-17T22:26:30.785620567Z 67 PC: 13006 | Get or set file attributes
2018-12-17T22:26:30.792400752Z 64 PC: 13768 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:26:30.793951639Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:30.795379318Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:26:30.797677249Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:26:30.799033683Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:30.800342502Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:30.808825809Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:30.810646859Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:26:30.812019791Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:26:30.814377966Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:26:30.815845354Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:26:30.817321876Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:26:30.818965431Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:26:30.82027047Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:26:30.821478236Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:26:30.822682633Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:26:30.823978183Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:26:30.825162563Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:26:30.826738193Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:30.828450878Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:26:30.829627325Z 76 PC: 134e0 | Terminate with return code (Return code = '0')