Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Nazi.8000.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:39.640133411Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:39.642115877Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:30:39.643150028Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:39.644953164Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:39.646934294Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:39.648251624Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:39.650154961Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:30:39.651350714Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:30:39.652746421Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:30:39.653898328Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:30:39.655144718Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:30:39.657014821Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:30:39.658233988Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:30:39.659482935Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:30:39.661274661Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:30:39.662635617Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:30:39.66372546Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:30:39.665694553Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:39.666900015Z 53 PC: 14c7a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:30:39.668161743Z 37 PC: 14c8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:39.671043556Z 37 PC: 14c97 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:39.67253593Z 37 PC: 14c9f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:39.674000873Z 37 PC: 14ca7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:39.676697039Z 68 PC: 1586c | I/O control for devices (Set for = '')
2018-12-17T22:30:39.777645976Z 37 PC: 14331 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:39.779117362Z 48 PC: 15592 | Get DOS version
2018-12-17T22:30:39.781569689Z 53 PC: 14a51 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:30:39.782758896Z 37 PC: 14a6d | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:30:39.783828958Z 53 PC: 14a51 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:30:39.78571Z 37 PC: 14a6d | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:30:39.787228766Z 53 PC: 14a51 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:39.788663932Z 37 PC: 14a6d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:39.790209733Z 51 PC: 1493f | Get or set Ctrl-Break
2018-12-17T22:30:39.791571094Z 60 PC: 153d0 | Create or truncate file
2018-12-17T22:30:39.809596676Z 65 PC: 15519 | Delete file (Filename = '\�')
2018-12-17T22:30:39.820191765Z 48 PC: 15592 | Get DOS version
2018-12-17T22:30:39.821802049Z 61 PC: 153d0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:30:39.828498073Z 66 PC: 15502 | Move file pointer
2018-12-17T22:30:39.830385582Z 63 PC: 154a3 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:30:39.837588448Z 62 PC: 15420 | Close file
2018-12-17T22:30:39.843853868Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:39.845200823Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:30:39.846728877Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:39.847810022Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:39.848884202Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:39.850530651Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:39.852277974Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:30:39.853322658Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:30:39.854813255Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:30:39.855648924Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:30:39.856499588Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:30:39.859929274Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:30:39.861227158Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:30:39.862268679Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:30:39.863710477Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:30:39.86465666Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:30:39.865679199Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:30:39.867509252Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:39.868489161Z 37 PC: 14dd1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:30:39.869415088Z 76 PC: 14e10 | Terminate with return code (Return code = '8')