Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Nazi.8297

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:46.566508966Z 53 PC: 149fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:46.576174676Z 53 PC: 149fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:35:46.577627274Z 53 PC: 149fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:46.579088291Z 53 PC: 149fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:46.580782484Z 53 PC: 149fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:46.582689678Z 53 PC: 149fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:46.584542758Z 53 PC: 149fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:35:46.598143881Z 53 PC: 149fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:35:46.610778063Z 53 PC: 149fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:35:46.631638667Z 53 PC: 149fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:35:46.633883278Z 53 PC: 149fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:35:46.635909514Z 53 PC: 149fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:35:46.6378288Z 53 PC: 149fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:35:46.63923835Z 53 PC: 149fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:35:46.641199091Z 53 PC: 149fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:35:46.642940016Z 53 PC: 149fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:35:46.64454625Z 53 PC: 149fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:35:46.66030048Z 53 PC: 149fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:46.66155152Z 53 PC: 149fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:35:46.663100008Z 37 PC: 14a0f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:46.664770161Z 37 PC: 14a17 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:46.665979396Z 37 PC: 14a1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:46.667078122Z 37 PC: 14a27 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:46.668972562Z 68 PC: 155e7 | I/O control for devices (Set for = '')
2018-12-17T22:35:46.818252061Z 37 PC: 140b1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:46.819654468Z 48 PC: 15312 | Get DOS version
2018-12-17T22:35:46.821175453Z 53 PC: 147d1 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:35:46.822589988Z 37 PC: 147ed | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:35:46.823704916Z 53 PC: 147d1 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:35:46.824823313Z 37 PC: 147ed | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:35:46.826302427Z 53 PC: 147d1 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:46.82740759Z 37 PC: 147ed | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:46.828389683Z 51 PC: 146bf | Get or set Ctrl-Break
2018-12-17T22:35:46.830334363Z 60 PC: 15150 | Create or truncate file
2018-12-17T22:35:46.8508751Z 65 PC: 15299 | Delete file (Filename = '\�')
2018-12-17T22:35:46.862896409Z 48 PC: 15312 | Get DOS version
2018-12-17T22:35:46.865513443Z 61 PC: 15150 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:46.874189307Z 66 PC: 15282 | Move file pointer
2018-12-17T22:35:46.87589668Z 63 PC: 15223 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:35:46.884099973Z 62 PC: 151a0 | Close file
2018-12-17T22:35:46.891544798Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:46.893386387Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:35:46.89590996Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:46.897525174Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:46.899836824Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:46.901730852Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:46.904934592Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:35:46.906743103Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:35:46.908665334Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:35:46.911658376Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:35:46.91342485Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:35:46.915173424Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:35:46.917972587Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:35:46.919742165Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:35:46.921411748Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:35:46.924063112Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:35:46.925832368Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:35:46.928000277Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:46.929984116Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:35:46.932265476Z 76 PC: 14b90 | Terminate with return code (Return code = '8')