Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Gula.7413

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:50.643681008Z 53 PC: 1378a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.645333135Z 53 PC: 1378a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:50.646782913Z 53 PC: 1378a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.648621543Z 53 PC: 1378a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:50.650595439Z 53 PC: 1378a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.652156905Z 53 PC: 1378a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.65366885Z 53 PC: 1378a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:50.65532419Z 53 PC: 1378a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:50.656491504Z 53 PC: 1378a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:50.657651413Z 53 PC: 1378a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:50.659707443Z 53 PC: 1378a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:50.661225864Z 53 PC: 1378a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:50.662746154Z 53 PC: 1378a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:50.668749401Z 53 PC: 1378a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:50.669960392Z 53 PC: 1378a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:50.671084919Z 53 PC: 1378a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:50.673019876Z 53 PC: 1378a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:50.674563522Z 53 PC: 1378a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.676264597Z 53 PC: 1378a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:50.678679037Z 37 PC: 1379f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.679854477Z 37 PC: 137a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.680949688Z 37 PC: 137af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.683323942Z 37 PC: 137b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.685247166Z 68 PC: 1441e | I/O control for devices (Set for = '')
2018-12-17T21:55:50.733269157Z 37 PC: 12fa1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.735781694Z 48 PC: 1402f | Get DOS version
2018-12-17T21:55:50.737343677Z 61 PC: 13ee1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:55:50.744291644Z 63 PC: 13fb4 | Read file or device (Read 7408 bytes on handle 5)
2018-12-17T21:55:50.753511955Z 62 PC: 13f31 | Close file
2018-12-17T21:55:50.755507054Z 26 PC: 1358b | Set disk transfer address
2018-12-17T21:55:50.756688469Z 78 PC: 13597 | Find first file
2018-12-17T21:55:50.765720396Z 61 PC: 13ee1 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:55:50.775418144Z 66 PC: 14013 | Move file pointer
2018-12-17T21:55:50.777814905Z 63 PC: 13fb4 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T21:55:50.783847456Z 26 PC: 135af | Set disk transfer address
2018-12-17T21:55:50.787195627Z 79 PC: 135b4 | Find next file
2018-12-17T21:55:50.790558423Z 48 PC: 1402f | Get DOS version
2018-12-17T21:55:50.793535769Z 61 PC: 13ee1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:55:50.800517313Z 66 PC: 1451d | Move file pointer
2018-12-17T21:55:50.802136061Z 66 PC: 1452b | Move file pointer
2018-12-17T21:55:50.804660476Z 66 PC: 14539 | Move file pointer
2018-12-17T21:55:50.806466488Z 66 PC: 14013 | Move file pointer
2018-12-17T21:55:50.808244485Z 63 PC: 13fb4 | Read file or device (Read 7413 bytes on handle 6)
2018-12-17T21:55:50.816755609Z 66 PC: 14013 | Move file pointer
2018-12-17T21:55:50.818668769Z 64 PC: 13fb4 | Write file or device (Write 7413 bytes on handle 6)
2018-12-17T21:55:50.845489386Z 66 PC: 1451d | Move file pointer
2018-12-17T21:55:50.847825573Z 66 PC: 1452b | Move file pointer
2018-12-17T21:55:50.849731491Z 66 PC: 14539 | Move file pointer
2018-12-17T21:55:50.852133711Z 66 PC: 14013 | Move file pointer
2018-12-17T21:55:50.854449097Z 64 PC: 13f12 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T21:55:50.864882148Z 53 PC: 136fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.866357762Z 37 PC: 13703 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.867960971Z 53 PC: 136fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:50.870166467Z 37 PC: 13703 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:50.871547288Z 53 PC: 136fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.872957325Z 37 PC: 13703 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.875066025Z 53 PC: 136fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:50.876483576Z 37 PC: 13703 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:50.877840301Z 53 PC: 136fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.880165863Z 37 PC: 13703 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.88156377Z 53 PC: 136fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.882944859Z 37 PC: 13703 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.88494534Z 53 PC: 136fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:50.886432573Z 37 PC: 13703 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:50.887810563Z 53 PC: 136fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:50.88999227Z 37 PC: 13703 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:50.891398506Z 53 PC: 136fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:50.892765921Z 37 PC: 13703 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:50.894489736Z 53 PC: 136fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:50.895911855Z 37 PC: 13703 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:50.897378335Z 53 PC: 136fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:50.899583811Z 37 PC: 13703 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:50.901144618Z 53 PC: 136fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:50.902656948Z 37 PC: 13703 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:50.90479067Z 53 PC: 136fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:50.906512629Z 37 PC: 13703 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:50.907905813Z 53 PC: 136fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:50.910034582Z 37 PC: 13703 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:50.911677781Z 53 PC: 136fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:50.913058867Z 37 PC: 13703 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:50.915124821Z 53 PC: 136fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:50.916784809Z 37 PC: 13703 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:50.918145976Z 53 PC: 136fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:50.919712332Z 37 PC: 13703 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:50.921593459Z 53 PC: 136fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.922745096Z 37 PC: 13703 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.923979443Z 53 PC: 136fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:50.926068698Z 37 PC: 13703 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:50.927915599Z 48 PC: 1402f | Get DOS version
2018-12-17T21:55:50.930599881Z 41 PC: 136b1 | Parse filename
2018-12-17T21:55:50.932617139Z 41 PC: 136bf | Parse filename
2018-12-17T21:55:50.933958011Z 75 PC: 136ca | Execute program
2018-12-17T21:55:50.954468336Z 80 PC: 1a789 | Set current PSP
2018-12-17T21:55:50.955623447Z 48 PC: 1a78e | Get DOS version
2018-12-17T21:55:50.957048381Z 99 PC: 20f70 | Get DBCS lead byte table pointer
2018-12-17T21:55:50.960054804Z 101 PC: 1a814 | Get extended country info
2018-12-17T21:55:50.961291048Z 99 PC: 1a81a | Get DBCS lead byte table pointer
2018-12-17T21:55:50.962444667Z 74 PC: 1a87c | Reallocate memory
2018-12-17T21:55:50.964458344Z 25 PC: 1a8b3 | Get default drive
2018-12-17T21:55:50.96560999Z 37 PC: 1a373 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:55:50.966631989Z 37 PC: 1a37a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.968334527Z 37 PC: 1a381 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.972349753Z 74 PC: 1951c | Reallocate memory
2018-12-17T21:55:50.973687284Z 72 PC: 1955d | Allocate memory
2018-12-17T21:55:50.975869523Z 72 PC: 19595 | Allocate memory
2018-12-17T21:55:50.97754849Z 72 PC: 1959d | Allocate memory