Sample viewer

vx.netlux.org/Virus.DOS.HLLP.7808

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:53.098122283Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.100618817Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:53.102292848Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.104064467Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.106273662Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.108353846Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:53.109955701Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:53.112057905Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:53.114986043Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:53.116849325Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:53.118711908Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:53.121106236Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:53.122707427Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:53.124290426Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:53.126175754Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:53.127498084Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:53.128776977Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.130606394Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:53.131829152Z 37 PC: 139fb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.132805161Z 37 PC: 13a03 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.134753368Z 37 PC: 13a0b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.135999303Z 37 PC: 13a13 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.137665989Z 68 PC: 14013 | I/O control for devices (Set for = '')
2018-12-17T22:34:53.222075034Z 37 PC: 13417 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.223896067Z 48 PC: 1454a | Get DOS version
2018-12-17T22:34:53.225907913Z 60 PC: 1430a | Create or truncate file
2018-12-17T22:34:53.246989672Z 62 PC: 1435a | Close file
2018-12-17T22:34:53.250116254Z 65 PC: 144df | Delete file (Filename = 'A:o.ooo')
2018-12-17T22:34:53.262618282Z 61 PC: 1430a | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:34:53.270629705Z 63 PC: 143dd | Read file or device (Read 7808 bytes on handle 5)
2018-12-17T22:34:53.280457038Z 25 PC: 145d7 | Get default drive
2018-12-17T22:34:53.282041638Z 71 PC: 145ea | Get current directory
2018-12-17T22:34:53.28612325Z 26 PC: 131f5 | Set disk transfer address
2018-12-17T22:34:53.288649484Z 78 PC: 13201 | Find first file
2018-12-17T22:34:53.297398364Z 61 PC: 1430a | Open file (Filename = 'A:\SLEEP.COM')
2018-12-17T22:34:53.305198512Z 63 PC: 143dd | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:34:53.313998008Z 61 PC: 1430a | Open file (Filename = 'A:\SLEEP.COM')
2018-12-17T22:34:53.322198211Z 63 PC: 143dd | Read file or device (Read 7808 bytes on handle 7)
2018-12-17T22:34:53.325504229Z 66 PC: 1443c | Move file pointer
2018-12-17T22:34:53.328111405Z 64 PC: 143dd | Write file or device (Write 7808 bytes on handle 7)
2018-12-17T22:34:53.337870944Z 62 PC: 1435a | Close file
2018-12-17T22:34:53.347184716Z 61 PC: 1430a | Open file (Filename = 'A:\SLEEP.COM')
2018-12-17T22:34:53.355945341Z 66 PC: 144a6 | Move file pointer
2018-12-17T22:34:53.358926419Z 66 PC: 144b4 | Move file pointer
2018-12-17T22:34:53.361050546Z 66 PC: 144c2 | Move file pointer
2018-12-17T22:34:53.363260456Z 66 PC: 1443c | Move file pointer
2018-12-17T22:34:53.365639345Z 64 PC: 143dd | Write file or device (Write 407 bytes on handle 7)
2018-12-17T22:34:53.375222413Z 62 PC: 1435a | Close file
2018-12-17T22:34:53.384707708Z 26 PC: 13219 | Set disk transfer address
2018-12-17T22:34:53.386601371Z 79 PC: 1321e | Find next file
2018-12-17T22:34:53.390576299Z 61 PC: 1430a | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:34:53.398284086Z 66 PC: 1443c | Move file pointer
2018-12-17T22:34:53.400561579Z 66 PC: 144a6 | Move file pointer
2018-12-17T22:34:53.402405567Z 66 PC: 144b4 | Move file pointer
2018-12-17T22:34:53.404298211Z 66 PC: 144c2 | Move file pointer
2018-12-17T22:34:53.407105538Z 66 PC: 1443c | Move file pointer
2018-12-17T22:34:53.409180347Z 63 PC: 143dd | Read file or device (Read 7808 bytes on handle 7)
2018-12-17T22:34:53.413064296Z 66 PC: 1443c | Move file pointer
2018-12-17T22:34:53.416097095Z 64 PC: 143dd | Write file or device (Write 7808 bytes on handle 7)
2018-12-17T22:34:53.425593041Z 66 PC: 1443c | Move file pointer
2018-12-17T22:34:53.427492256Z 63 PC: 143dd | Read file or device (Read 28 bytes on handle 7)
2018-12-17T22:34:53.435387364Z 53 PC: 1325c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.43796269Z 37 PC: 13265 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.440456594Z 53 PC: 1325c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:53.44205941Z 37 PC: 13265 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:53.444952542Z 53 PC: 1325c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.446599992Z 37 PC: 13265 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.448181529Z 53 PC: 1325c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.450826701Z 37 PC: 13265 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.452445676Z 53 PC: 1325c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.45409301Z 37 PC: 13265 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.45696057Z 53 PC: 1325c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:53.458469734Z 37 PC: 13265 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:53.459913555Z 53 PC: 1325c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:53.461384033Z 37 PC: 13265 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:53.463679389Z 53 PC: 1325c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:53.465367162Z 37 PC: 13265 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:53.466965007Z 53 PC: 1325c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:53.469477239Z 37 PC: 13265 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:53.471321662Z 53 PC: 1325c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:53.473064195Z 37 PC: 13265 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:53.475260643Z 53 PC: 1325c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:53.476784984Z 37 PC: 13265 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:53.478126855Z 53 PC: 1325c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:53.480615172Z 37 PC: 13265 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:53.481958312Z 53 PC: 1325c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:53.483428021Z 37 PC: 13265 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:53.486197389Z 53 PC: 1325c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:53.487615263Z 37 PC: 13265 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:53.489017202Z 53 PC: 1325c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:53.490782132Z 37 PC: 13265 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:53.493347196Z 53 PC: 1325c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:53.495055612Z 37 PC: 13265 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:53.496678891Z 53 PC: 1325c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.499397225Z 37 PC: 13265 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.501043903Z 53 PC: 1325c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:53.502724648Z 37 PC: 13265 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:53.505785587Z 41 PC: 132e4 | Parse filename
2018-12-17T22:34:53.507834671Z 41 PC: 132f2 | Parse filename
2018-12-17T22:34:53.513240662Z 75 PC: 132fd | Execute program
2018-12-17T22:34:53.530748225Z 76 PC: 19765 | Terminate with return code (Return code = '0')
2018-12-17T22:34:53.542968632Z 53 PC: 1325c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.544561754Z 37 PC: 13265 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.549765741Z 53 PC: 1325c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:53.551801163Z 37 PC: 13265 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:53.554034608Z 53 PC: 1325c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.557644539Z 37 PC: 13265 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.561409716Z 53 PC: 1325c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.563627521Z 37 PC: 13265 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.565671645Z 53 PC: 1325c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.568506892Z 37 PC: 13265 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.570287791Z 53 PC: 1325c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:53.572149632Z 37 PC: 13265 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:53.574869931Z 53 PC: 1325c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:53.576585362Z 37 PC: 13265 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:53.578258917Z 53 PC: 1325c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:53.580371973Z 37 PC: 13265 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:53.581936726Z 53 PC: 1325c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:53.583400608Z 37 PC: 13265 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:53.586114592Z 53 PC: 1325c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:53.587891706Z 37 PC: 13265 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:53.589547005Z 53 PC: 1325c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:53.591274111Z 37 PC: 13265 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:53.593801511Z 53 PC: 1325c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:53.595076444Z 37 PC: 13265 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:53.59642273Z 53 PC: 1325c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:53.599386312Z 37 PC: 13265 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:53.600713792Z 53 PC: 1325c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:53.602068968Z 37 PC: 13265 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:53.604388949Z 53 PC: 1325c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:53.606351667Z 37 PC: 13265 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:53.60774391Z 53 PC: 1325c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:53.60947895Z 37 PC: 13265 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:53.610904054Z 53 PC: 1325c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.612245666Z 37 PC: 13265 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.614313466Z 53 PC: 1325c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:53.615948184Z 37 PC: 13265 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:53.617682439Z 61 PC: 1430a | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:34:53.627314372Z 64 PC: 143dd | Write file or device (Write 7808 bytes on handle 8)
2018-12-17T22:34:53.637125228Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:53.639333197Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:53.641908805Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:53.643953957Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:53.645308487Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:53.648118198Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:53.650186758Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:53.652021774Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:53.654551941Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:53.655897684Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:53.657399866Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:53.660231526Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:53.661931263Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:53.663682986Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:53.665651786Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:53.668059864Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:53.66987481Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:53.671663251Z 37 PC: 13af5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:53.674698612Z 76 PC: 13b34 | Terminate with return code (Return code = '0')