Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Mossa.5504

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:13.41591115Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:13.41759673Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:13.418719837Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:13.419868229Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:13.421903705Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:13.42298441Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:13.42403596Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:13.425515055Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:13.427095367Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:13.428644451Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:13.430695302Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:13.432223439Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:13.433549387Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:13.435024618Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:13.437021037Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:13.438498395Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:13.439821123Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:13.453646503Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:13.454720713Z 53 PC: 133a2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:13.45579489Z 37 PC: 133b7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:13.457453572Z 37 PC: 133bf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:13.458572921Z 37 PC: 133c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:13.459656232Z 37 PC: 133cf | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:13.462070983Z 68 PC: 1373f | I/O control for devices (Set for = '')
2018-12-17T21:55:13.463680661Z 25 PC: 13c99 | Get default drive
2018-12-17T21:55:13.465087304Z 71 PC: 13cac | Get current directory
2018-12-17T21:55:13.469113306Z 26 PC: 13225 | Set disk transfer address
2018-12-17T21:55:13.470387589Z 78 PC: 13231 | Find first file
2018-12-17T21:55:13.476863294Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.478820945Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.481942352Z 26 PC: 13225 | Set disk transfer address
2018-12-17T21:55:13.483805298Z 78 PC: 13231 | Find first file
2018-12-17T21:55:13.490306792Z 26 PC: 13225 | Set disk transfer address
2018-12-17T21:55:13.491320431Z 78 PC: 13231 | Find first file
2018-12-17T21:55:13.497473476Z 26 PC: 13225 | Set disk transfer address
2018-12-17T21:55:13.49969745Z 78 PC: 13231 | Find first file
2018-12-17T21:55:13.505604429Z 26 PC: 13225 | Set disk transfer address
2018-12-17T21:55:13.506597183Z 78 PC: 13231 | Find first file
2018-12-17T21:55:13.51596418Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.51701269Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.520399061Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.521870727Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.525264256Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.5262251Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.529600861Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.533466403Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.536843113Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.537794798Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.541707098Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.542881044Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.549420114Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.551061434Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.554392207Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.555375174Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.560570609Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.561614247Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.564864537Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.566592034Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.571195363Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.572234051Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.577284013Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.578368347Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.581806691Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.58381152Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.587290566Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.588355234Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.595473526Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.596871369Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.600455745Z 26 PC: 13249 | Set disk transfer address
2018-12-17T21:55:13.602998081Z 79 PC: 1324e | Find next file
2018-12-17T21:55:13.606797731Z 26 PC: 13225 | Set disk transfer address
2018-12-17T21:55:13.608327058Z 78 PC: 13231 | Find first file
2018-12-17T21:55:13.625378914Z 86 PC: 13c5f | Rename file
2018-12-17T21:55:13.969525958Z 60 PC: 13ae0 | Create or truncate file
2018-12-17T21:55:13.984809768Z 61 PC: 13ae0 | Open file (Filename = 'A:\.exe')
2018-12-17T21:55:13.990199161Z 64 PC: 13bb3 | Write file or device (Write 5504 bytes on handle 5)
2018-12-17T21:55:14.189563911Z 62 PC: 13b30 | Close file
2018-12-17T21:55:14.428673582Z 53 PC: 1328c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:14.431024894Z 37 PC: 13295 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:14.433058689Z 53 PC: 1328c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:14.434584339Z 37 PC: 13295 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:14.436210375Z 53 PC: 1328c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:14.437575697Z 37 PC: 13295 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:14.4388386Z 53 PC: 1328c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:14.440161529Z 37 PC: 13295 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:14.441990653Z 53 PC: 1328c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:14.44309079Z 37 PC: 13295 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:14.444153688Z 53 PC: 1328c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:14.446085226Z 37 PC: 13295 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:14.447122421Z 53 PC: 1328c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:14.448200927Z 37 PC: 13295 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:14.450521707Z 53 PC: 1328c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:14.451584833Z 37 PC: 13295 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:14.45270153Z 53 PC: 1328c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:14.454763151Z 37 PC: 13295 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:14.455786338Z 53 PC: 1328c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:14.456821856Z 37 PC: 13295 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:14.458723532Z 53 PC: 1328c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:14.459990747Z 37 PC: 13295 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:14.461199861Z 53 PC: 1328c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:14.463327646Z 37 PC: 13295 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:14.464276139Z 53 PC: 1328c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:14.465333822Z 37 PC: 13295 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:14.467440259Z 53 PC: 1328c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:14.468447361Z 37 PC: 13295 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:14.469383456Z 53 PC: 1328c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:14.470685281Z 37 PC: 13295 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:14.471917602Z 53 PC: 1328c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:14.473211342Z 37 PC: 13295 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:14.47555912Z 53 PC: 1328c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:14.476811217Z 37 PC: 13295 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:14.478130799Z 53 PC: 1328c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:14.479892614Z 37 PC: 13295 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:14.481258344Z 53 PC: 1328c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:14.482449896Z 37 PC: 13295 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:14.484502819Z 41 PC: 13315 | Parse filename
2018-12-17T21:55:14.485827902Z 41 PC: 13323 | Parse filename
2018-12-17T21:55:14.487138814Z 75 PC: 1332e | Execute program
2018-12-17T21:55:14.490806955Z 53 PC: 1328c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:14.49186453Z 37 PC: 13295 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:14.492811548Z 53 PC: 1328c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:14.494177554Z 37 PC: 13295 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:14.495828586Z 53 PC: 1328c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:14.497723425Z 37 PC: 13295 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:14.499306965Z 53 PC: 1328c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:14.500442421Z 37 PC: 13295 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:14.501510569Z 53 PC: 1328c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:14.503156128Z 37 PC: 13295 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:14.504347043Z 53 PC: 1328c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:14.50588902Z 37 PC: 13295 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:14.507699417Z 53 PC: 1328c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:14.509572778Z 37 PC: 13295 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:14.510694132Z 53 PC: 1328c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:14.512478307Z 37 PC: 13295 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:14.513724234Z 53 PC: 1328c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:14.514968985Z 37 PC: 13295 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:14.516777578Z 53 PC: 1328c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:14.517929998Z 37 PC: 13295 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:14.51916506Z 53 PC: 1328c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:14.521185616Z 37 PC: 13295 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:14.522252321Z 53 PC: 1328c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:14.523286873Z 37 PC: 13295 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:14.525653799Z 53 PC: 1328c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:14.526662211Z 37 PC: 13295 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:14.527633399Z 53 PC: 1328c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:14.550346897Z 37 PC: 13295 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:14.551487317Z 53 PC: 1328c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:14.552562457Z 37 PC: 13295 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:14.55439311Z 53 PC: 1328c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:14.555664821Z 37 PC: 13295 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:14.556670787Z 53 PC: 1328c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:14.558283166Z 37 PC: 13295 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:14.559315839Z 53 PC: 1328c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:14.560454665Z 37 PC: 13295 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:14.562089888Z 53 PC: 1328c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:14.563118298Z 37 PC: 13295 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:14.56432672Z 64 PC: 13842 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:55:14.566417931Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:14.567399563Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:14.568378896Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:14.573333013Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:14.586274876Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:14.587625179Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:14.589255453Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:14.590405996Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:14.591732067Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:14.593593688Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:14.594785117Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:14.597373416Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:14.598595958Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:14.599667282Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:14.60103835Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:14.602507767Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:14.603627486Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:14.605428925Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:14.606654995Z 37 PC: 134b6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:14.607803812Z 76 PC: 134f5 | Terminate with return code (Return code = '0')