Sample viewer

vx.netlux.org/Virus.DOS.HLLP.3072.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:29.912185368Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:29.913314376Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:35:29.915122477Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:29.9163027Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:29.917408895Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:29.919302246Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:35:29.920403561Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:35:29.921499657Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '220' AKA 'UNKNOWN!')
2018-12-17T22:35:29.92312203Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '254' AKA 'UNKNOWN!')
2018-12-17T22:35:29.924234556Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:35:29.925354787Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:35:29.927039807Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:35:29.928248534Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:35:29.92942473Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:35:29.931277395Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:35:29.932450986Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:35:29.933648632Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:29.935592618Z 53 PC: 12de6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:35:29.936801946Z 37 PC: 12dfb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:29.937835123Z 37 PC: 12e03 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:29.939293348Z 37 PC: 12e0b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:29.940627781Z 37 PC: 12e13 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:29.942044818Z 68 PC: 131b6 | I/O control for devices (Set for = '')
2018-12-17T22:35:29.943720982Z 48 PC: 134d5 | Get DOS version
2018-12-17T22:35:29.945864863Z 61 PC: 13350 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:29.952820979Z 63 PC: 13423 | Read file or device (Read 3072 bytes on handle 5)
2018-12-17T22:35:29.959834001Z 62 PC: 133a0 | Close file
2018-12-17T22:35:29.962305396Z 48 PC: 134d5 | Get DOS version
2018-12-17T22:35:29.964145367Z 61 PC: 13350 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:29.972432549Z 66 PC: 13482 | Move file pointer
2018-12-17T22:35:29.974935483Z 63 PC: 13423 | Read file or device (Read 3072 bytes on handle 5)
2018-12-17T22:35:29.983434423Z 66 PC: 13482 | Move file pointer
2018-12-17T22:35:29.985317374Z 64 PC: 13423 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:35:30.000252374Z 62 PC: 133a0 | Close file
2018-12-17T22:35:30.010944757Z 48 PC: 134d5 | Get DOS version
2018-12-17T22:35:30.012893742Z 41 PC: 12d5c | Parse filename
2018-12-17T22:35:30.015732947Z 41 PC: 12d6a | Parse filename
2018-12-17T22:35:30.026930297Z 75 PC: 12d75 | Execute program
2018-12-17T22:35:30.043266164Z 48 PC: 165dc | Get DOS version
2018-12-17T22:35:30.045059808Z 9 PC: 165ee | Display string (String= ' Incorrect DOS version ')
2018-12-17T22:35:30.058251659Z 48 PC: 134d5 | Get DOS version
2018-12-17T22:35:30.060245799Z 61 PC: 13350 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:30.069061292Z 66 PC: 13482 | Move file pointer
2018-12-17T22:35:30.071108321Z 64 PC: 13423 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:35:30.079022053Z 62 PC: 133a0 | Close file
2018-12-17T22:35:30.087261966Z 64 PC: 132b9 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:35:30.090017945Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:30.091398144Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:35:30.09351825Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:30.096730534Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:30.098224546Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:30.099611257Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:35:30.101819619Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:35:30.10333983Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '220' AKA 'UNKNOWN!')
2018-12-17T22:35:30.104640689Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '254' AKA 'UNKNOWN!')
2018-12-17T22:35:30.106646421Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:35:30.108615644Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:35:30.109914951Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:35:30.112062549Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:35:30.113345154Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:35:30.114510389Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:35:30.115666217Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:35:30.117559057Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:30.118672515Z 37 PC: 12ef5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:35:30.119831399Z 76 PC: 12f34 | Terminate with return code (Return code = '0')