Sample viewer

vx.netlux.org/Virus.DOS.HLLP.UPI.4641

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:16.381442941Z 53 PC: 13652 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:16.38412137Z 53 PC: 13652 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:16.386133466Z 53 PC: 13652 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:16.387983108Z 53 PC: 13652 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:16.389895061Z 53 PC: 13652 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:16.392136917Z 53 PC: 13652 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.393899091Z 53 PC: 13652 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:16.395662699Z 53 PC: 13652 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:16.403525224Z 53 PC: 13652 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:16.406044993Z 53 PC: 13652 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:16.411102284Z 53 PC: 13652 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:16.41336818Z 53 PC: 13652 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:16.421413137Z 53 PC: 13652 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:16.423538259Z 53 PC: 13652 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:16.426432131Z 53 PC: 13652 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:16.428179399Z 53 PC: 13652 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:16.429913819Z 53 PC: 13652 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:16.432390334Z 53 PC: 13652 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:16.434235063Z 53 PC: 13652 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:16.435939226Z 37 PC: 13667 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:16.438465861Z 37 PC: 1366f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:16.44026561Z 37 PC: 13677 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.442572305Z 37 PC: 1367f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:16.445078955Z 68 PC: 139f1 | I/O control for devices (Set for = '')
2018-12-17T22:31:16.447248441Z 53 PC: 13499 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:16.448977259Z 53 PC: 13499 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.45076801Z 37 PC: 134b5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:16.464160564Z 37 PC: 134b5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.465820392Z 48 PC: 140eb | Get DOS version
2018-12-17T22:31:16.469228636Z 61 PC: 13eda | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:31:16.477404873Z 63 PC: 13fad | Read file or device (Read 4641 bytes on handle 5)
2018-12-17T22:31:16.485654498Z 62 PC: 13f2a | Close file
2018-12-17T22:31:16.489155512Z 48 PC: 140eb | Get DOS version
2018-12-17T22:31:16.49161467Z 67 PC: 1339b | Get or set file attributes
2018-12-17T22:31:16.498379882Z 67 PC: 133c2 | Get or set file attributes
2018-12-17T22:31:16.515754691Z 61 PC: 13eda | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:31:16.525793037Z 87 PC: 133dc | Get or set file date and time
2018-12-17T22:31:16.531075685Z 63 PC: 13fad | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:31:16.540502227Z 87 PC: 13409 | Get or set file date and time
2018-12-17T22:31:16.543510291Z 62 PC: 13f2a | Close file
2018-12-17T22:31:16.551274863Z 67 PC: 133c2 | Get or set file attributes
2018-12-17T22:31:16.562295861Z 53 PC: 134cb | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:16.564205467Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:16.565944103Z 53 PC: 134cb | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:16.567314032Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:16.569172759Z 53 PC: 134cb | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:16.570560257Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:16.571855383Z 53 PC: 134cb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:16.5737044Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:16.575032832Z 53 PC: 134cb | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:16.576352521Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:16.57779771Z 53 PC: 134cb | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.579386196Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.580748101Z 53 PC: 134cb | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:16.582171439Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:16.583591944Z 53 PC: 134cb | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:16.584970173Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:16.586276182Z 53 PC: 134cb | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:16.58868487Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:16.589931979Z 53 PC: 134cb | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:16.591312826Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:16.593351086Z 53 PC: 134cb | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:16.594864804Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:16.596252256Z 53 PC: 134cb | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:16.598716465Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:16.600053721Z 53 PC: 134cb | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:16.601729706Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:16.603769972Z 53 PC: 134cb | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:16.605676759Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:16.607329748Z 53 PC: 134cb | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:16.609237216Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:16.611520309Z 53 PC: 134cb | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:16.613135808Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:16.614918499Z 53 PC: 134cb | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:16.618162639Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:16.620018806Z 53 PC: 134cb | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:16.621930932Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:16.624121002Z 53 PC: 134cb | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:16.625659565Z 37 PC: 134d4 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:16.627599327Z 48 PC: 140eb | Get DOS version
2018-12-17T22:31:16.630383179Z 41 PC: 13554 | Parse filename
2018-12-17T22:31:16.632203208Z 41 PC: 13562 | Parse filename
2018-12-17T22:31:16.633795569Z 75 PC: 1356d | Execute program
2018-12-17T22:31:16.658497784Z 80 PC: 184b9 | Set current PSP
2018-12-17T22:31:16.65955856Z 48 PC: 184be | Get DOS version
2018-12-17T22:31:16.661363488Z 99 PC: 1eca0 | Get DBCS lead byte table pointer
2018-12-17T22:31:16.665404306Z 101 PC: 18544 | Get extended country info
2018-12-17T22:31:16.66726452Z 99 PC: 1854a | Get DBCS lead byte table pointer
2018-12-17T22:31:16.669300665Z 74 PC: 185ac | Reallocate memory
2018-12-17T22:31:16.671402634Z 25 PC: 185e3 | Get default drive
2018-12-17T22:31:16.674158851Z 37 PC: 180a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:31:16.676071214Z 37 PC: 180aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:16.677946425Z 37 PC: 180b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:16.68427038Z 74 PC: 1724c | Reallocate memory
2018-12-17T22:31:16.686440342Z 72 PC: 1728d | Allocate memory
2018-12-17T22:31:16.688776571Z 72 PC: 172c5 | Allocate memory
2018-12-17T22:31:16.691764506Z 72 PC: 172cd | Allocate memory