Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3072.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:46.203971972Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:46.205712597Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:46.207883671Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:46.209230327Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:46.210606905Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:46.213358982Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:46.215003991Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:46.216614044Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:46.218948575Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:46.221262186Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:46.223581345Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:46.226846252Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:46.229194616Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:46.231534419Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:46.234258842Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:46.236881631Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:46.238393698Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:46.239471978Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:28:46.241466691Z 37 PC: 12dbb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:46.242449749Z 37 PC: 12dc3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:46.243484655Z 37 PC: 12dcb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:46.2452668Z 37 PC: 12dd3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:46.246820881Z 68 PC: 13176 | I/O control for devices (Set for = '')
2018-12-17T22:28:46.248398489Z 48 PC: 134ea | Get DOS version
2018-12-17T22:28:46.251022959Z 61 PC: 13310 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:28:46.258963985Z 63 PC: 133e3 | Read file or device (Read 3072 bytes on handle 5)
2018-12-17T22:28:46.267017813Z 62 PC: 13360 | Close file
2018-12-17T22:28:46.270107484Z 48 PC: 134ea | Get DOS version
2018-12-17T22:28:46.272197331Z 61 PC: 13310 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:28:46.280647343Z 66 PC: 134ac | Move file pointer
2018-12-17T22:28:46.28258562Z 66 PC: 134ba | Move file pointer
2018-12-17T22:28:46.284544226Z 66 PC: 134c8 | Move file pointer
2018-12-17T22:28:46.286269162Z 66 PC: 13442 | Move file pointer
2018-12-17T22:28:46.28792852Z 63 PC: 133e3 | Read file or device (Read 3072 bytes on handle 5)
2018-12-17T22:28:46.297342621Z 66 PC: 13442 | Move file pointer
2018-12-17T22:28:46.29866577Z 64 PC: 133e3 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:28:46.310890806Z 62 PC: 13360 | Close file
2018-12-17T22:28:46.320669211Z 48 PC: 134ea | Get DOS version
2018-12-17T22:28:46.323011137Z 41 PC: 12d1c | Parse filename
2018-12-17T22:28:46.325159994Z 41 PC: 12d2a | Parse filename
2018-12-17T22:28:46.328440464Z 75 PC: 12d35 | Execute program
2018-12-17T22:28:46.346447651Z 51 PC: 16180 | Get or set Ctrl-Break
2018-12-17T22:28:46.347899417Z 51 PC: 16180 | Get or set Ctrl-Break
2018-12-17T22:28:46.350478422Z 48 PC: 16180 | Get DOS version
2018-12-17T22:28:46.352537728Z 64 PC: 16180 | Write file or device (Write 23 bytes on handle 2)
2018-12-17T22:28:46.358100923Z 51 PC: 16180 | Get or set Ctrl-Break
2018-12-17T22:28:46.359499995Z 76 PC: 16180 | Terminate with return code (Return code = '255')
2018-12-17T22:28:46.364376911Z 48 PC: 134ea | Get DOS version
2018-12-17T22:28:46.366474169Z 61 PC: 13310 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:28:46.375237058Z 64 PC: 133e3 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:28:46.383822463Z 62 PC: 13360 | Close file
2018-12-17T22:28:46.389242244Z 64 PC: 13279 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:28:46.390853736Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:46.392707213Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:46.393903302Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:28:46.395375996Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:46.397744514Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:46.399407887Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:46.400955947Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:46.403525471Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:46.405935702Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:46.407445827Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:46.41168577Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:46.413776813Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:46.415122093Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:46.416410487Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:46.418847538Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:46.420141418Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:46.421445819Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:28:46.423495224Z 37 PC: 12eb5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:28:46.424799338Z 76 PC: 12ef4 | Terminate with return code (Return code = '0')