Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5400

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:28.093869403Z 53 PC: 139ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:28.096179401Z 53 PC: 139ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:28.097355616Z 53 PC: 139ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:28.098513779Z 53 PC: 139ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:28.101508966Z 53 PC: 139ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:28.102711609Z 53 PC: 139ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:28.103906175Z 53 PC: 139ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:28.105636098Z 53 PC: 139ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:28.106732606Z 53 PC: 139ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:28.107829251Z 53 PC: 139ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:28.109651649Z 53 PC: 139ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:28.111145559Z 53 PC: 139ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:28.11261153Z 53 PC: 139ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:28.114515085Z 53 PC: 139ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:28.116332517Z 53 PC: 139ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:28.118197869Z 53 PC: 139ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:28.120566312Z 53 PC: 139ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:28.122407469Z 53 PC: 139ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:28.123759268Z 53 PC: 139ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:28:28.125187183Z 37 PC: 139cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:28.126217366Z 37 PC: 139d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:28.127155898Z 37 PC: 139df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:28.128249032Z 37 PC: 139e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:28.12999796Z 68 PC: 143fa | I/O control for devices (Set for = '')
2018-12-17T22:28:28.131293888Z 48 PC: 1403f | Get DOS version
2018-12-17T22:28:28.132760489Z 53 PC: 137ff | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:28:28.134397157Z 37 PC: 1381b | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:28:28.136329716Z 53 PC: 137ff | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:28:28.138230785Z 37 PC: 1381b | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:28:28.140029457Z 53 PC: 137ff | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:28.141881854Z 37 PC: 1381b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:28.143654805Z 51 PC: 136ed | Get or set Ctrl-Break
2018-12-17T22:28:28.145377117Z 25 PC: 140cc | Get default drive
2018-12-17T22:28:28.147256656Z 71 PC: 140df | Get current directory
2018-12-17T22:28:28.150462643Z 60 PC: 13e7d | Create or truncate file
2018-12-17T22:28:28.16891562Z 65 PC: 13fc6 | Delete file (Filename = 'Aasf')
2018-12-17T22:28:28.181391403Z 48 PC: 1403f | Get DOS version
2018-12-17T22:28:28.185758755Z 61 PC: 13e7d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:28:28.193607747Z 63 PC: 13f50 | Read file or device (Read 5400 bytes on handle 6)
2018-12-17T22:28:28.202585902Z 9 PC: 12a52 | Display string (Could not find end pointer)
2018-12-17T22:28:28.205008734Z 64 PC: 13dd8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:28:28.206577885Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:28.207747954Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:28.208989542Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:28.210037953Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:28.211615804Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:28.213110737Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:28.214147496Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:28.21546884Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:28.217076136Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:28.21818334Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:28.219263417Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:28.220608257Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:28.221708245Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:28.222948403Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:28.224837195Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:28.226026626Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:28.22718258Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:28.237542642Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:28.238613437Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:28:28.239662962Z 76 PC: 13b50 | Terminate with return code (Return code = '8')