Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DarkFox.4997

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:52.858337675Z 53 PC: 1347a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:52.859915701Z 53 PC: 1347a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:52.861096386Z 53 PC: 1347a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:52.862218143Z 53 PC: 1347a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:52.864373483Z 53 PC: 1347a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:52.865506023Z 53 PC: 1347a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:52.866735173Z 53 PC: 1347a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:52.868277247Z 53 PC: 1347a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:52.869544596Z 53 PC: 1347a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:52.870657982Z 53 PC: 1347a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:52.872189935Z 53 PC: 1347a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:52.873986235Z 53 PC: 1347a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:52.875204416Z 53 PC: 1347a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:52.877066476Z 53 PC: 1347a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:52.878135994Z 53 PC: 1347a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:52.879216382Z 53 PC: 1347a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:52.880780943Z 53 PC: 1347a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:52.882061332Z 53 PC: 1347a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:52.884024728Z 53 PC: 1347a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:52.885367502Z 37 PC: 1348f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:52.886730262Z 37 PC: 13497 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:52.887753646Z 37 PC: 1349f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:52.889089936Z 37 PC: 134a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:52.890528467Z 68 PC: 140dd | I/O control for devices (Set for = '')
2018-12-17T22:31:52.892858319Z 26 PC: 1327d | Set disk transfer address
2018-12-17T22:31:52.894038493Z 78 PC: 13289 | Find first file
2018-12-17T22:31:52.89981871Z 67 PC: 13206 | Get or set file attributes
2018-12-17T22:31:52.905116438Z 61 PC: 13ba0 | Open file (Filename = 'C:\DO\')
2018-12-17T22:31:52.911579749Z 67 PC: 13206 | Get or set file attributes
2018-12-17T22:31:52.917049998Z 26 PC: 132a1 | Set disk transfer address
2018-12-17T22:31:52.918102748Z 79 PC: 132a6 | Find next file
2018-12-17T22:31:52.92004633Z 26 PC: 1327d | Set disk transfer address
2018-12-17T22:31:52.921272953Z 78 PC: 13289 | Find first file
2018-12-17T22:31:52.927560385Z 67 PC: 13206 | Get or set file attributes
2018-12-17T22:31:52.932749387Z 61 PC: 13ba0 | Open file (Filename = 'C:\DO\')
2018-12-17T22:31:52.938636489Z 67 PC: 13206 | Get or set file attributes
2018-12-17T22:31:52.943609821Z 26 PC: 132a1 | Set disk transfer address
2018-12-17T22:31:52.944577641Z 79 PC: 132a6 | Find next file
2018-12-17T22:31:52.946785591Z 48 PC: 13cee | Get DOS version
2018-12-17T22:31:52.948157557Z 67 PC: 131df | Get or set file attributes
2018-12-17T22:31:52.954538816Z 67 PC: 13206 | Get or set file attributes
2018-12-17T22:31:52.971060677Z 61 PC: 13ba0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:31:52.977647411Z 87 PC: 13220 | Get or set file date and time
2018-12-17T22:31:52.979158044Z 66 PC: 141dc | Move file pointer
2018-12-17T22:31:52.98079901Z 66 PC: 141ea | Move file pointer
2018-12-17T22:31:52.982157311Z 66 PC: 141f8 | Move file pointer
2018-12-17T22:31:52.983724367Z 63 PC: 13c73 | Read file or device (Read 4996 bytes on handle 5)
2018-12-17T22:31:52.992139638Z 63 PC: 13c73 | Read file or device (Read 5121 bytes on handle 5)
2018-12-17T22:31:52.999676227Z 62 PC: 13bf0 | Close file
2018-12-17T22:31:53.001547906Z 48 PC: 13cee | Get DOS version
2018-12-17T22:31:53.00360651Z 60 PC: 13ba0 | Create or truncate file
2018-12-17T22:31:53.016771716Z 64 PC: 13c73 | Write file or device (Write 5121 bytes on handle 5)
2018-12-17T22:31:53.026183685Z 62 PC: 13bf0 | Close file
2018-12-17T22:31:53.035874895Z 53 PC: 133ec | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:53.03708843Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:53.038205677Z 53 PC: 133ec | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:53.04132319Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:53.04250456Z 53 PC: 133ec | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:53.043682214Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:53.0460226Z 53 PC: 133ec | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:53.047213063Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:53.048339729Z 53 PC: 133ec | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:53.050468156Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:53.05156951Z 53 PC: 133ec | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:53.052684422Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:53.055225822Z 53 PC: 133ec | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:53.056600024Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:53.057852096Z 53 PC: 133ec | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:53.05963034Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:53.060653394Z 53 PC: 133ec | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:53.061717819Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:53.06319686Z 53 PC: 133ec | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:53.064281158Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:53.065327027Z 53 PC: 133ec | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:53.067209021Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:53.068162345Z 53 PC: 133ec | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:53.069136811Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:53.070307287Z 53 PC: 133ec | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:53.071941745Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:53.073203542Z 53 PC: 133ec | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:53.074741924Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:53.075853625Z 53 PC: 133ec | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:53.077031577Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:53.078405253Z 53 PC: 133ec | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:53.080167302Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:53.081218433Z 53 PC: 133ec | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:53.08227096Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:53.087328243Z 53 PC: 133ec | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:53.088622104Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:53.089861951Z 53 PC: 133ec | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:53.091337415Z 37 PC: 133f5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:53.092322537Z 48 PC: 13cee | Get DOS version
2018-12-17T22:31:53.093556482Z 41 PC: 133a3 | Parse filename
2018-12-17T22:31:53.094952691Z 41 PC: 133b1 | Parse filename
2018-12-17T22:31:53.096215089Z 75 PC: 133bc | Execute program