Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Merlin.4329

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:36:03.651536533Z 53 PC: 12a60 | Get interrupt vector (Interrupt = '144' AKA 'UNKNOWN!')
2018-12-17T22:36:03.653115178Z 53 PC: 12a6f | Get interrupt vector (Interrupt = '145' AKA 'UNKNOWN!')
2018-12-17T22:36:03.654257057Z 37 PC: 12a82 | Set interrupt vector (Interrupt = '144' AKA 'UNKNOWN!')
2018-12-17T22:36:03.655266301Z 37 PC: 12a8b | Set interrupt vector (Interrupt = '145' AKA 'UNKNOWN!')
2018-12-17T22:36:03.658219101Z 53 PC: 1443a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:36:03.659675474Z 53 PC: 1443a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:36:03.661211438Z 53 PC: 1443a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:36:03.66273378Z 53 PC: 1443a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:36:03.664266478Z 53 PC: 1443a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:36:03.665783756Z 53 PC: 1443a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:36:03.667305015Z 53 PC: 1443a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:36:03.668831417Z 53 PC: 1443a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:36:03.669884711Z 53 PC: 1443a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:36:03.670993718Z 53 PC: 1443a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:36:03.672006439Z 53 PC: 1443a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:36:03.672994328Z 53 PC: 1443a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:36:03.674464664Z 53 PC: 1443a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:36:03.675432547Z 53 PC: 1443a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:36:03.676391054Z 53 PC: 1443a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:36:03.682454426Z 53 PC: 1443a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:36:03.683335392Z 53 PC: 1443a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:36:03.684166474Z 53 PC: 1443a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:36:03.685504693Z 53 PC: 1443a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:36:03.686377505Z 37 PC: 1444f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:36:03.687094453Z 37 PC: 14457 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:36:03.688546012Z 37 PC: 1445f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:36:03.689507982Z 37 PC: 14467 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:36:03.690561624Z 68 PC: 14e0d | I/O control for devices (Set for = '�0���')
2018-12-17T22:36:03.702866492Z 44 PC: 14284 | Get time 0x14284: mov word ptr cs:[0x754], cx
0x14289: mov word ptr cs:[0x757], dx
0x1428e: ret
0x1428f: push bx
0x14290: push cx
0x14291: push dx
0x14292: push ax
0x14293: mov ax, 0
0x14296: mov bx, 0
0x14299: mov cx, ax
0x1429b: mov dx, 0x8405
0x1429e: mul dx
0x142a0: shl cx, 3
0x142a3: add ch, cl
0x142a5: add dx, cx
0x142a7: add dx, bx
0x142a9: shl bx, 2
0x142ac: add dx, bx
0x142ae: add dh, bl
0x142b0: mov cl, 5
2018-12-17T22:36:03.70550752Z 60 PC: 14b00 | Create or truncate file
2018-12-17T22:36:04.749269941Z 62 PC: 14b50 | Close file
2018-12-17T22:36:04.754028521Z 65 PC: 14c49 | Delete file (Filename = '�')
2018-12-17T22:36:04.913015336Z 26 PC: 14315 | Set disk transfer address
2018-12-17T22:36:04.914173617Z 78 PC: 14321 | Find first file
2018-12-17T22:36:04.919009517Z 64 PC: 14858 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:36:04.920685274Z 37 PC: 14591 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:36:04.922487556Z 37 PC: 14591 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:36:04.923970156Z 37 PC: 14591 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:36:04.924988469Z 37 PC: 14591 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:36:04.925973529Z 37 PC: 14591 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:36:04.927391398Z 37 PC: 14591 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:36:04.928352978Z 37 PC: 14591 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:36:04.929328157Z 37 PC: 14591 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:36:04.931002489Z 37 PC: 14591 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:36:04.931972667Z 37 PC: 14591 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:36:04.932911504Z 37 PC: 14591 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:36:04.934302195Z 37 PC: 14591 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:36:04.93532682Z 37 PC: 14591 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:36:04.936309309Z 37 PC: 14591 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:36:04.937769011Z 37 PC: 14591 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:36:04.938655093Z 37 PC: 14591 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:36:04.939741337Z 37 PC: 14591 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:36:04.94093132Z 37 PC: 14591 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:36:04.941742707Z 37 PC: 14591 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:36:04.942620277Z 37 PC: 12af9 | Set interrupt vector (Interrupt = '144' AKA 'UNKNOWN!')
2018-12-17T22:36:04.944048588Z 37 PC: 12b03 | Set interrupt vector (Interrupt = '145' AKA 'UNKNOWN!')
2018-12-17T22:36:04.945022967Z 98 PC: 12b07 | Get current PSP
2018-12-17T22:36:04.945700444Z 26 PC: 12b12 | Set disk transfer address