Sample viewer

vx.netlux.org/Virus.DOS.HLLC.4336

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:47.611365632Z 53 PC: 1301a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:47.613563069Z 53 PC: 1301a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:47.614927677Z 53 PC: 1301a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:47.616251546Z 53 PC: 1301a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:47.617797553Z 53 PC: 1301a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:47.620244628Z 53 PC: 1301a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:47.621979242Z 53 PC: 1301a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:47.623686275Z 53 PC: 1301a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:47.626260131Z 53 PC: 1301a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:47.627634996Z 53 PC: 1301a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:47.628918399Z 53 PC: 1301a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:47.631012043Z 53 PC: 1301a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:47.632837095Z 53 PC: 1301a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:47.634724362Z 53 PC: 1301a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:47.637409925Z 53 PC: 1301a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:47.638965272Z 53 PC: 1301a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:47.640598507Z 53 PC: 1301a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:47.642891027Z 53 PC: 1301a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:47.644619786Z 53 PC: 1301a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:47.646268879Z 37 PC: 1302f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:47.648306115Z 37 PC: 13037 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:47.650202255Z 37 PC: 1303f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:47.655986281Z 37 PC: 13047 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:47.65834289Z 68 PC: 13905 | I/O control for devices (Set for = '')
2018-12-17T22:32:47.660794055Z 48 PC: 1362b | Get DOS version
2018-12-17T22:32:47.66316632Z 48 PC: 1362b | Get DOS version
2018-12-17T22:32:47.665703Z 61 PC: 134dd | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:32:47.675188993Z 63 PC: 135b0 | Read file or device (Read 4336 bytes on handle 5)
2018-12-17T22:32:47.68345652Z 62 PC: 1352d | Close file
2018-12-17T22:32:47.685500233Z 26 PC: 12e65 | Set disk transfer address
2018-12-17T22:32:47.687861251Z 78 PC: 12e71 | Find first file
2018-12-17T22:32:47.696536518Z 61 PC: 134dd | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:47.704187218Z 60 PC: 134dd | Create or truncate file
2018-12-17T22:32:47.735725079Z 64 PC: 135b0 | Write file or device (Write 4336 bytes on handle 5)
2018-12-17T22:32:47.750379769Z 61 PC: 134dd | Open file (Filename = 'TEST.EXE')
2018-12-17T22:32:47.769104295Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.772227407Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.775384265Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.777225385Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.791271582Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.7937615Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.797042551Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.799108194Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.803441964Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.805536519Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.808849347Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.811971762Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.815244279Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.817308521Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.821766068Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.824440819Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.827720282Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.830379405Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.8337174Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.838164912Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.842176771Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.84484286Z 63 PC: 135b0 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:32:47.848149775Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.850208679Z 63 PC: 135b0 | Read file or device (Read 1000 bytes on handle 6)
2018-12-17T22:32:47.859974855Z 66 PC: 1360f | Move file pointer
2018-12-17T22:32:47.862222818Z 64 PC: 135b0 | Write file or device (Write 1000 bytes on handle 6)
2018-12-17T22:32:47.871719701Z 62 PC: 1352d | Close file
2018-12-17T22:32:47.882135834Z 62 PC: 1352d | Close file
2018-12-17T22:32:47.890648708Z 26 PC: 12e89 | Set disk transfer address
2018-12-17T22:32:47.893090687Z 79 PC: 12e8e | Find next file
2018-12-17T22:32:47.901600835Z 64 PC: 13438 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:32:47.904944907Z 37 PC: 13171 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:47.90658204Z 37 PC: 13171 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:47.908976278Z 37 PC: 13171 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:47.911708099Z 37 PC: 13171 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:47.913055483Z 37 PC: 13171 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:47.914966603Z 37 PC: 13171 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:47.917370154Z 37 PC: 13171 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:47.919246218Z 37 PC: 13171 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:47.920526863Z 37 PC: 13171 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:47.922914231Z 37 PC: 13171 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:47.92419956Z 37 PC: 13171 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:47.925563286Z 37 PC: 13171 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:47.928082223Z 37 PC: 13171 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:47.929437799Z 37 PC: 13171 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:47.9307307Z 37 PC: 13171 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:47.932750845Z 37 PC: 13171 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:47.934263909Z 37 PC: 13171 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:47.935977581Z 37 PC: 13171 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:47.937885256Z 37 PC: 13171 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:47.939652813Z 76 PC: 131b0 | Terminate with return code (Return code = '0')