Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Merlin.3693

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:07.962797435Z 53 PC: 132d8 | Get interrupt vector (Interrupt = '144' AKA 'UNKNOWN!')
2018-12-17T22:28:07.964639396Z 53 PC: 132e7 | Get interrupt vector (Interrupt = '145' AKA 'UNKNOWN!')
2018-12-17T22:28:07.966197311Z 37 PC: 132fa | Set interrupt vector (Interrupt = '144' AKA 'UNKNOWN!')
2018-12-17T22:28:07.969314432Z 37 PC: 13303 | Set interrupt vector (Interrupt = '145' AKA 'UNKNOWN!')
2018-12-17T22:28:07.971873256Z 53 PC: 1462a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:07.97366382Z 53 PC: 1462a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:07.976887821Z 53 PC: 1462a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:07.979551673Z 53 PC: 1462a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:07.982256839Z 53 PC: 1462a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:07.984725077Z 53 PC: 1462a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:07.987594528Z 53 PC: 1462a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:07.988797881Z 53 PC: 1462a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:07.989991944Z 53 PC: 1462a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:07.991787556Z 53 PC: 1462a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:07.992736116Z 53 PC: 1462a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:07.993681246Z 53 PC: 1462a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:07.995725609Z 53 PC: 1462a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:07.996939175Z 53 PC: 1462a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:07.997931063Z 53 PC: 1462a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:07.999382223Z 53 PC: 1462a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:08.000378004Z 53 PC: 1462a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:08.001296565Z 53 PC: 1462a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:08.002830019Z 53 PC: 1462a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:28:08.003863258Z 37 PC: 1463f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:08.004813164Z 37 PC: 14647 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:08.006016311Z 37 PC: 1464f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:08.007514869Z 37 PC: 14657 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:08.009217111Z 68 PC: 14ffd | I/O control for devices (Set for = '������ �u��˜�g.��ܙ���V�,')
2018-12-17T22:28:08.011379521Z 60 PC: 14cf0 | Create or truncate file
2018-12-17T22:28:08.026714921Z 62 PC: 14d40 | Close file
2018-12-17T22:28:08.028116914Z 65 PC: 14e39 | Delete file (Filename = '�')
2018-12-17T22:28:08.035153579Z 26 PC: 14507 | Set disk transfer address
2018-12-17T22:28:08.036918328Z 78 PC: 14513 | Find first file
2018-12-17T22:28:08.041457203Z 61 PC: 14cf0 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:28:08.048683417Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.051409839Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.053121072Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.054815974Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.056904701Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.058496673Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.060171846Z 63 PC: 14dc3 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:28:08.069000155Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.070549009Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.072523108Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.074971539Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.076624001Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.078229766Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.0831251Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.084665633Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.086097276Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.087799733Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.089509465Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.090951699Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.092526349Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.094246797Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.09554009Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.096966428Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.098726481Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.100191895Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.102536116Z 66 PC: 150fc | Move file pointer
2018-12-17T22:28:08.104396595Z 66 PC: 1510a | Move file pointer
2018-12-17T22:28:08.10638253Z 66 PC: 15118 | Move file pointer
2018-12-17T22:28:08.108555537Z 66 PC: 14e22 | Move file pointer
2018-12-17T22:28:08.111134946Z 64 PC: 14dc3 | Write file or device (Write 3693 bytes on handle 5)
2018-12-17T22:28:08.121051532Z 66 PC: 14e22 | Move file pointer
2018-12-17T22:28:08.122598981Z 64 PC: 14dc3 | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:28:08.125889048Z 62 PC: 14d40 | Close file
2018-12-17T22:28:08.131875906Z 67 PC: 144af | Get or set file attributes
2018-12-17T22:28:08.136222861Z 67 PC: 144d6 | Get or set file attributes
2018-12-17T22:28:08.1455898Z 26 PC: 1452b | Set disk transfer address
2018-12-17T22:28:08.147430579Z 79 PC: 14530 | Find next file
2018-12-17T22:28:08.151195843Z 64 PC: 14a48 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:28:08.153469092Z 37 PC: 14781 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:08.155506394Z 37 PC: 14781 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:08.157017641Z 37 PC: 14781 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:08.158518772Z 37 PC: 14781 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:08.170420888Z 37 PC: 14781 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:08.172290273Z 37 PC: 14781 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:08.174037636Z 37 PC: 14781 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:08.176739562Z 37 PC: 14781 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:08.177966607Z 37 PC: 14781 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:08.179225289Z 37 PC: 14781 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:08.181086059Z 37 PC: 14781 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:08.182476587Z 37 PC: 14781 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:08.183670973Z 37 PC: 14781 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:08.185747525Z 37 PC: 14781 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:08.187599091Z 37 PC: 14781 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:08.188891488Z 37 PC: 14781 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:08.191336309Z 37 PC: 14781 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:08.192589935Z 37 PC: 14781 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:08.194074983Z 37 PC: 14781 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:28:08.195687329Z 37 PC: 1334c | Set interrupt vector (Interrupt = '144' AKA 'UNKNOWN!')
2018-12-17T22:28:08.197867943Z 37 PC: 13356 | Set interrupt vector (Interrupt = '145' AKA 'UNKNOWN!')
2018-12-17T22:28:08.200149404Z 98 PC: 1335a | Get current PSP
2018-12-17T22:28:08.201358028Z 26 PC: 13365 | Set disk transfer address
2018-12-17T22:28:08.210701924Z 9 PC: 12e49 | Display string (Could not find end pointer)