Sample viewer

vx.netlux.org/Virus.DOS.HLLP.WYD.10127

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:46.03455038Z 53 PC: 151ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:33:46.036378608Z 53 PC: 151ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:33:46.037732187Z 53 PC: 151ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:33:46.038756933Z 53 PC: 151ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:33:46.040720531Z 53 PC: 151ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:33:46.04203953Z 53 PC: 151ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:46.043648548Z 53 PC: 151ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:33:46.045494171Z 53 PC: 151ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:33:46.04703718Z 53 PC: 151ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:33:46.048861422Z 53 PC: 151ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:33:46.050597205Z 53 PC: 151ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:33:46.052756858Z 53 PC: 151ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:33:46.058596584Z 53 PC: 151ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:33:46.061233072Z 53 PC: 151ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:33:46.062609895Z 53 PC: 151ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:33:46.063879019Z 53 PC: 151ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:33:46.069525781Z 53 PC: 151ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:33:46.073658489Z 53 PC: 151ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:33:46.075325812Z 53 PC: 151ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:33:46.077153788Z 37 PC: 151df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:33:46.078260098Z 37 PC: 151e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:33:46.081770636Z 37 PC: 151ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:46.083326931Z 37 PC: 151f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:33:46.084763843Z 68 PC: 15f1c | I/O control for devices (Set for = '')
2018-12-17T22:33:46.256319976Z 37 PC: 14871 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:33:46.259110501Z 53 PC: 14f7a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:33:46.265208329Z 53 PC: 14f7a | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:33:46.267287547Z 37 PC: 14f96 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:33:46.269507805Z 37 PC: 14f96 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:33:46.2715209Z 48 PC: 15b2d | Get DOS version
2018-12-17T22:33:46.281451633Z 61 PC: 1596b | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:33:46.297186644Z 66 PC: 15a9d | Move file pointer
2018-12-17T22:33:46.30826799Z 63 PC: 15a3e | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:33:46.316412354Z 63 PC: 15a3e | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:33:46.319470281Z 62 PC: 159bb | Close file
2018-12-17T22:33:46.322465776Z 48 PC: 15b2d | Get DOS version
2018-12-17T22:33:46.324287452Z 61 PC: 1596b | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:33:46.333065546Z 66 PC: 1601b | Move file pointer
2018-12-17T22:33:46.334772354Z 66 PC: 16029 | Move file pointer
2018-12-17T22:33:46.336113721Z 66 PC: 16037 | Move file pointer
2018-12-17T22:33:46.337848077Z 63 PC: 15a3e | Read file or device (Read 9792 bytes on handle 5)
2018-12-17T22:33:46.346183201Z 66 PC: 15a9d | Move file pointer
2018-12-17T22:33:46.348017492Z 63 PC: 15a3e | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:33:46.351680805Z 63 PC: 15a3e | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:33:46.354338841Z 63 PC: 15a3e | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:33:46.357012461Z 63 PC: 15a3e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:33:46.360057119Z 66 PC: 15a9d | Move file pointer
2018-12-17T22:33:46.376305874Z 66 PC: 1601b | Move file pointer
2018-12-17T22:33:46.377862588Z 66 PC: 16029 | Move file pointer
2018-12-17T22:33:46.379454006Z 66 PC: 16037 | Move file pointer
2018-12-17T22:33:46.381656999Z 62 PC: 159bb | Close file
2018-12-17T22:33:46.383518853Z 42 PC: 15142 | Get date 0x15142: pushf
0x15143: push es
0x15144: push di
0x15145: push bp
0x15146: mov bp, sp
0x15148: les di, ptr [bp + 0x12]
0x1514b: cld
0x1514c: stosw word ptr es:[di], ax
0x1514d: mov ax, bx
0x1514f: stosw word ptr es:[di], ax
0x15150: mov ax, cx
0x15152: stosw word ptr es:[di], ax
0x15153: mov ax, dx
0x15155: stosw word ptr es:[di], ax
0x15156: pop ax
0x15157: stosw word ptr es:[di], ax
0x15158: mov ax, si
0x1515a: stosw word ptr es:[di], ax
0x1515b: pop ax
0x1515c: stosw word ptr es:[di], ax
2018-12-17T22:33:51.90695103Z 8 PC: 15142 | Console input without echo