Sample viewer

vx.netlux.org/Virus.DOS.HLLP.4768

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:43.230417426Z 53 PC: 13222 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:43.231766876Z 53 PC: 13222 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:26:43.234156739Z 53 PC: 13222 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:26:43.237351599Z 53 PC: 13222 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:43.239626532Z 53 PC: 13222 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:43.242162525Z 53 PC: 13222 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:43.245211331Z 53 PC: 13222 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:26:43.247205464Z 53 PC: 13222 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:26:43.249339224Z 53 PC: 13222 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:26:43.251456328Z 53 PC: 13222 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:26:43.253167713Z 53 PC: 13222 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:26:43.254824343Z 53 PC: 13222 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:26:43.257108231Z 53 PC: 13222 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:26:43.258573268Z 53 PC: 13222 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:26:43.260053403Z 53 PC: 13222 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:26:43.263315838Z 53 PC: 13222 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:26:43.264832879Z 53 PC: 13222 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:26:43.266563365Z 53 PC: 13222 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:43.270069498Z 53 PC: 13222 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:26:43.272479304Z 37 PC: 13237 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:43.274554708Z 37 PC: 1323f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:43.27812532Z 37 PC: 13247 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:43.282788539Z 37 PC: 1324f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:43.28493675Z 68 PC: 137cf | I/O control for devices (Set for = '')
2018-12-17T22:26:43.287770016Z 48 PC: 13f94 | Get DOS version
2018-12-17T22:26:43.290705908Z 61 PC: 13dba | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:26:43.304449011Z 63 PC: 13e8d | Read file or device (Read 4767 bytes on handle 5)
2018-12-17T22:26:43.31352289Z 66 PC: 13f56 | Move file pointer
2018-12-17T22:26:43.316439505Z 66 PC: 13f64 | Move file pointer
2018-12-17T22:26:43.318862089Z 66 PC: 13f72 | Move file pointer
2018-12-17T22:26:43.321626132Z 66 PC: 13eec | Move file pointer
2018-12-17T22:26:43.325865136Z 63 PC: 13e8d | Read file or device (Read 4767 bytes on handle 5)
2018-12-17T22:26:43.335020995Z 66 PC: 13eec | Move file pointer
2018-12-17T22:26:43.337037313Z 64 PC: 13e8d | Write file or device (Write 4767 bytes on handle 5)
2018-12-17T22:26:43.352750461Z 66 PC: 13eec | Move file pointer
2018-12-17T22:26:43.355040327Z 64 PC: 13deb | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:26:43.365298485Z 62 PC: 13e0a | Close file
2018-12-17T22:26:43.374278888Z 26 PC: 13035 | Set disk transfer address
2018-12-17T22:26:43.376869149Z 78 PC: 13041 | Find first file
2018-12-17T22:26:43.384992414Z 61 PC: 13dba | Open file (Filename = 'TEST.EXE')
2018-12-17T22:26:43.392783499Z 66 PC: 13f56 | Move file pointer
2018-12-17T22:26:43.395711737Z 66 PC: 13f64 | Move file pointer
2018-12-17T22:26:43.398070918Z 66 PC: 13f72 | Move file pointer
2018-12-17T22:26:43.400159939Z 26 PC: 13059 | Set disk transfer address
2018-12-17T22:26:43.402615223Z 79 PC: 1305e | Find next file
2018-12-17T22:26:43.407217015Z 53 PC: 1309c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:43.408918124Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:26:43.410789574Z 53 PC: 1309c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:26:43.412989096Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:26:43.414334554Z 53 PC: 1309c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:26:43.415673173Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:26:43.417887796Z 53 PC: 1309c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:43.419299119Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:43.420625363Z 53 PC: 1309c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:43.422704051Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:43.424011199Z 53 PC: 1309c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:43.425314664Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:26:43.427610304Z 53 PC: 1309c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:26:43.428932546Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:26:43.43019779Z 53 PC: 1309c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:26:43.432076169Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:26:43.433400581Z 53 PC: 1309c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:26:43.435273334Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:26:43.436809369Z 53 PC: 1309c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:26:43.438858259Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:26:43.440483106Z 53 PC: 1309c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:26:43.442136995Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:26:43.444498439Z 53 PC: 1309c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:26:43.446683277Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:26:43.448292338Z 53 PC: 1309c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:26:43.450938393Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:26:43.452594121Z 53 PC: 1309c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:26:43.454243816Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:26:43.457793558Z 53 PC: 1309c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:26:43.459216913Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:26:43.460602769Z 53 PC: 1309c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:26:43.463312966Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:26:43.464720925Z 53 PC: 1309c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:26:43.466153306Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:26:43.468344431Z 53 PC: 1309c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:43.469903036Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:26:43.471366168Z 53 PC: 1309c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:26:43.473165923Z 37 PC: 130a5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:26:43.475606159Z 41 PC: 13125 | Parse filename
2018-12-17T22:26:43.477768506Z 41 PC: 13133 | Parse filename
2018-12-17T22:26:43.480736129Z 75 PC: 1313e | Execute program