Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Energy.6480

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:43.579772735Z 53 PC: 1324a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:43.588495305Z 53 PC: 1324a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:29:43.591093446Z 53 PC: 1324a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:29:43.592695121Z 53 PC: 1324a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:43.594547407Z 53 PC: 1324a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:43.596198622Z 53 PC: 1324a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:43.597673648Z 53 PC: 1324a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:29:43.600565248Z 53 PC: 1324a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:29:43.601760416Z 53 PC: 1324a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:29:43.602842872Z 53 PC: 1324a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:29:43.604151747Z 53 PC: 1324a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:29:43.605464427Z 53 PC: 1324a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:29:43.606506992Z 53 PC: 1324a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:29:43.607707627Z 53 PC: 1324a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:29:43.609516359Z 53 PC: 1324a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:29:43.611100823Z 53 PC: 1324a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:29:43.612653311Z 53 PC: 1324a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:29:43.615099538Z 53 PC: 1324a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:43.616528455Z 53 PC: 1324a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:29:43.617963721Z 37 PC: 1325f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:43.62034596Z 37 PC: 13267 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:43.621641365Z 37 PC: 1326f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:43.622983407Z 37 PC: 13277 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:43.625533787Z 68 PC: 1410c | I/O control for devices (Set for = 'dddddd]����>��$��� �u��>��;�!�W��2�������_��V�w�^����1��7�u�9�&�G&�W3�5�;�=�Ìَ��.��tD���')
2018-12-17T22:29:43.627430971Z 26 PC: 12fe9 | Set disk transfer address
2018-12-17T22:29:43.628577301Z 78 PC: 12ff5 | Find first file
2018-12-17T22:29:43.637548027Z 26 PC: 1300d | Set disk transfer address
2018-12-17T22:29:43.646691137Z 79 PC: 13012 | Find next file
2018-12-17T22:29:43.649573533Z 25 PC: 13dde | Get default drive
2018-12-17T22:29:43.650959098Z 71 PC: 13df1 | Get current directory
2018-12-17T22:29:43.653981164Z 14 PC: 13e37 | Set default drive (Drive = 'C')
2018-12-17T22:29:43.655147619Z 25 PC: 13e3b | Get default drive
2018-12-17T22:29:43.656650583Z 59 PC: 13ea5 | Change current directory
2018-12-17T22:29:43.660439072Z 26 PC: 12fe9 | Set disk transfer address
2018-12-17T22:29:43.661666474Z 78 PC: 12ff5 | Find first file
2018-12-17T22:29:43.681400328Z 26 PC: 12fe9 | Set disk transfer address
2018-12-17T22:29:43.682647369Z 78 PC: 12ff5 | Find first file
2018-12-17T22:29:43.687921472Z 26 PC: 1300d | Set disk transfer address
2018-12-17T22:29:43.689157361Z 79 PC: 13012 | Find next file
2018-12-17T22:29:43.692033393Z 26 PC: 1300d | Set disk transfer address
2018-12-17T22:29:43.69301867Z 79 PC: 13012 | Find next file
2018-12-17T22:29:43.695831146Z 59 PC: 13ea5 | Change current directory
2018-12-17T22:29:43.702815879Z 26 PC: 12fe9 | Set disk transfer address
2018-12-17T22:29:43.703805169Z 78 PC: 12ff5 | Find first file
2018-12-17T22:29:43.7123035Z 25 PC: 13dde | Get default drive
2018-12-17T22:29:43.713519231Z 71 PC: 13df1 | Get current directory
2018-12-17T22:29:43.715279168Z 67 PC: 12fb8 | Get or set file attributes
2018-12-17T22:29:44.050328536Z 88 PC: 12b4f | case 0xGet or set allocation strateg:
2018-12-17T22:29:44.052283267Z 53 PC: 131bc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:44.05399242Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:44.055697622Z 53 PC: 131bc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:29:44.058394483Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:29:44.060062381Z 53 PC: 131bc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:29:44.061783624Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:29:44.064374319Z 53 PC: 131bc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:44.065705595Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:44.066875225Z 53 PC: 131bc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:44.069231556Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:44.070819935Z 53 PC: 131bc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:44.072387893Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:44.074835968Z 53 PC: 131bc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:29:44.076408808Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:29:44.077927862Z 53 PC: 131bc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:29:44.080152142Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:29:44.081815373Z 53 PC: 131bc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:29:44.083317863Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:29:44.085470672Z 53 PC: 131bc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:29:44.087123786Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:29:44.088892048Z 53 PC: 131bc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:29:44.091448389Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:29:44.092833745Z 53 PC: 131bc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:29:44.094607706Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:29:44.096691752Z 53 PC: 131bc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:29:44.098227296Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:29:44.09980332Z 53 PC: 131bc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:29:44.102103888Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:29:44.103726432Z 53 PC: 131bc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:29:44.105328793Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:29:44.10711445Z 53 PC: 131bc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:29:44.108583238Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:29:44.109744418Z 53 PC: 131bc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:29:44.11136402Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:29:44.112382721Z 53 PC: 131bc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:44.113433991Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:44.115452375Z 53 PC: 131bc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:29:44.116526448Z 37 PC: 131c5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:29:44.118200758Z 41 PC: 13173 | Parse filename
2018-12-17T22:29:44.120242393Z 41 PC: 13181 | Parse filename
2018-12-17T22:29:44.121558085Z 75 PC: 1318c | Execute program
2018-12-17T22:29:44.145018916Z 80 PC: 17e69 | Set current PSP
2018-12-17T22:29:44.146692408Z 48 PC: 17e6e | Get DOS version
2018-12-17T22:29:44.148090202Z 99 PC: 1e650 | Get DBCS lead byte table pointer
2018-12-17T22:29:44.150444901Z 101 PC: 17ef4 | Get extended country info
2018-12-17T22:29:44.152026086Z 99 PC: 17efa | Get DBCS lead byte table pointer
2018-12-17T22:29:44.153143984Z 74 PC: 17f5c | Reallocate memory
2018-12-17T22:29:44.154370282Z 25 PC: 17f93 | Get default drive
2018-12-17T22:29:44.155974381Z 37 PC: 17a53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:29:44.157069345Z 37 PC: 17a5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:44.158035485Z 37 PC: 17a61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:44.162769962Z 74 PC: 16bfc | Reallocate memory
2018-12-17T22:29:44.164276077Z 72 PC: 16c3d | Allocate memory
2018-12-17T22:29:44.165747528Z 72 PC: 16c75 | Allocate memory
2018-12-17T22:29:44.175905961Z 72 PC: 16c7d | Allocate memory