Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Frost.6960

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:33.536982692Z 53 PC: 136fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.53857835Z 53 PC: 136fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:33.539797572Z 53 PC: 136fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:33.540943106Z 53 PC: 136fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:33.542692194Z 53 PC: 136fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:33.543736727Z 53 PC: 136fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:33.544745922Z 53 PC: 136fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:33.546017634Z 53 PC: 136fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:33.547380431Z 53 PC: 136fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:33.548680907Z 53 PC: 136fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:33.550163816Z 53 PC: 136fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:33.55152229Z 53 PC: 136fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:33.552618039Z 53 PC: 136fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:33.553754847Z 53 PC: 136fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:33.555295731Z 53 PC: 136fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:33.556279301Z 53 PC: 136fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:33.557252522Z 53 PC: 136fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:33.559050651Z 53 PC: 136fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:33.560161368Z 53 PC: 136fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:33.561248915Z 37 PC: 1370f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.562959223Z 37 PC: 13717 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:33.564264287Z 37 PC: 1371f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:33.565599841Z 37 PC: 13727 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:33.567796037Z 68 PC: 14257 | I/O control for devices (Set for = '')
2018-12-17T22:34:33.570319369Z 48 PC: 13f82 | Get DOS version
2018-12-17T22:34:33.572383351Z 48 PC: 13f82 | Get DOS version
2018-12-17T22:34:33.577218048Z 26 PC: 1351d | Set disk transfer address
2018-12-17T22:34:33.578318575Z 78 PC: 13529 | Find first file
2018-12-17T22:34:33.584296297Z 60 PC: 13dc0 | Create or truncate file
2018-12-17T22:34:33.603035293Z 65 PC: 13f09 | Delete file (Filename = '\�')
2018-12-17T22:34:33.614156241Z 60 PC: 13dc0 | Create or truncate file
2018-12-17T22:34:33.625188215Z 65 PC: 13f09 | Delete file (Filename = 'A:\�')
2018-12-17T22:34:33.63548071Z 48 PC: 13f82 | Get DOS version
2018-12-17T22:34:33.637013715Z 61 PC: 13dc0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:34:33.643621338Z 63 PC: 13e93 | Read file or device (Read 5555 bytes on handle 7)
2018-12-17T22:34:33.651187885Z 62 PC: 13e10 | Close file
2018-12-17T22:34:33.653002235Z 253 PC: 12f31 | UNKNOWN!
2018-12-17T22:34:33.653724772Z 48 PC: 13f82 | Get DOS version
2018-12-17T22:34:33.655156139Z 26 PC: 1351d | Set disk transfer address
2018-12-17T22:34:33.656849978Z 78 PC: 13529 | Find first file
2018-12-17T22:34:33.663994418Z 48 PC: 13f82 | Get DOS version
2018-12-17T22:34:33.665668835Z 67 PC: 134a6 | Get or set file attributes
2018-12-17T22:34:33.678868923Z 61 PC: 13dc0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:34:33.685577361Z 173 PC: 12f9f | UNKNOWN!
2018-12-17T22:34:33.686822515Z 186 PC: 13671 | UNKNOWN!
2018-12-17T22:34:33.688247736Z 53 PC: 135fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:33.689567135Z 37 PC: 13616 | Set interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-17T22:34:33.690819102Z 37 PC: 13616 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:33.692393144Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '228' AKA 'UNKNOWN!')
2018-12-17T22:34:33.694141021Z 64 PC: 12e7a | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:34:33.696018636Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.697797064Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.699208911Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.700628192Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.70237424Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.703717873Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.705036049Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.70650713Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.707829421Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.709200073Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.711708368Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.713072336Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.714420391Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.716234869Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.71760795Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.718948695Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.720725723Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.722084633Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.723396486Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.725147792Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.726488801Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.727787274Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.730036301Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.731360951Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.73266838Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.734784824Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.736170945Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:33.737377763Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:33.739126596Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:33.740354631Z 37 PC: 12e7a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:33.741405461Z 37 PC: 13851 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:33.742835549Z 37 PC: 13851 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:33.743860347Z 37 PC: 13851 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:33.74496432Z 37 PC: 13851 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:33.746794009Z 37 PC: 13851 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:33.747941594Z 37 PC: 13851 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:33.749070178Z 37 PC: 13851 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:33.751406768Z 37 PC: 13851 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:33.752349209Z 37 PC: 13851 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:33.753311483Z 37 PC: 13851 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:33.755139363Z 37 PC: 13851 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:33.756067672Z 37 PC: 13851 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:33.756880763Z 37 PC: 13851 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:33.758338156Z 37 PC: 13851 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:33.759319428Z 37 PC: 13851 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:33.76034259Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.762799401Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.764705016Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.766757089Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.769325884Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.771361192Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.773358105Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.775752258Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.777785879Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.77969471Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.782230079Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.784132161Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.78595834Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.788675312Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.790603566Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.792666975Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.795705668Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.797885077Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.800016703Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.813232938Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.815500444Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.817775914Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.821388081Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.823722724Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.825933607Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.82918758Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.832700757Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.83493811Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.837753412Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.839662352Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.841477623Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.844674447Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.846867387Z 6 PC: 138d8 | Direct console I/O
2018-12-17T22:34:33.850734765Z 76 PC: 13890 | Terminate with return code (Return code = '202')