Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Agent.6780

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:00.599114574Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:00.601275026Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:00.602977971Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:00.604965726Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:00.607348649Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:00.609465438Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:00.611082922Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:00.6126288Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:00.615418654Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:00.617022411Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:00.618658139Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:00.623769249Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:00.625045677Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:00.626715149Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:00.629109083Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:00.63092929Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:00.632539861Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:00.638629985Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:00.648383869Z 53 PC: 13d3a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:00.650025248Z 37 PC: 13d4f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:00.65315724Z 37 PC: 13d57 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:00.655266324Z 37 PC: 13d5f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:00.656766776Z 37 PC: 13d67 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:00.658771583Z 68 PC: 149b1 | I/O control for devices (Set for = '')
2018-12-17T22:38:00.724234198Z 37 PC: 13761 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:00.726621269Z 48 PC: 145c2 | Get DOS version
2018-12-17T22:38:00.72850697Z 61 PC: 14400 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:38:00.73797347Z 63 PC: 144d3 | Read file or device (Read 6780 bytes on handle 5)
2018-12-17T22:38:00.746374151Z 62 PC: 14450 | Close file
2018-12-17T22:38:00.749064416Z 60 PC: 14400 | Create or truncate file
2018-12-17T22:38:00.769621911Z 65 PC: 14549 | Delete file (Filename = '$$$$$$$$.$$$')
2018-12-17T22:38:00.795402329Z 26 PC: 134c5 | Set disk transfer address
2018-12-17T22:38:00.796874547Z 78 PC: 134d1 | Find first file
2018-12-17T22:38:00.81077773Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.813300928Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.819289982Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.842141873Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.847849914Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.850761769Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.867568901Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.87019262Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.874014589Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.891022001Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.895965584Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.897716119Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.901488384Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.903578051Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.907152582Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.908658985Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.913182322Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.914544392Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.925820949Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.928421955Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.932018187Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.933468834Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.952436949Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.95411635Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.957877013Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.959331568Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.964126479Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:00.965633173Z 79 PC: 134ee | Find next file
2018-12-17T22:38:00.970086798Z 61 PC: 14400 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:38:00.978111356Z 66 PC: 14532 | Move file pointer
2018-12-17T22:38:00.979988892Z 63 PC: 144d3 | Read file or device (Read 5 bytes on handle 6)
2018-12-17T22:38:00.992916757Z 62 PC: 14450 | Close file
2018-12-17T22:38:01.004384767Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.006300806Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.011543791Z 26 PC: 134c5 | Set disk transfer address
2018-12-17T22:38:01.016423378Z 78 PC: 134d1 | Find first file
2018-12-17T22:38:01.025399881Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.026878329Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.02994253Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.032487768Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.035565555Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.037020038Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.041112996Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.042598338Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.045676405Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.04796144Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.051393006Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.05289526Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.056700313Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.059299724Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.062328648Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.063799262Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.067865008Z 26 PC: 134e9 | Set disk transfer address
2018-12-17T22:38:01.069343778Z 79 PC: 134ee | Find next file
2018-12-17T22:38:01.07240858Z 61 PC: 14400 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:38:01.080598493Z 66 PC: 14ab0 | Move file pointer
2018-12-17T22:38:01.082464606Z 66 PC: 14abe | Move file pointer
2018-12-17T22:38:01.084251859Z 66 PC: 14acc | Move file pointer
2018-12-17T22:38:01.086928727Z 66 PC: 14532 | Move file pointer
2018-12-17T22:38:01.089169298Z 63 PC: 144d3 | Read file or device (Read 6780 bytes on handle 6)
2018-12-17T22:38:01.098473862Z 66 PC: 14ab0 | Move file pointer
2018-12-17T22:38:01.101093952Z 66 PC: 14abe | Move file pointer
2018-12-17T22:38:01.103328171Z 66 PC: 14acc | Move file pointer
2018-12-17T22:38:01.105182021Z 66 PC: 14532 | Move file pointer
2018-12-17T22:38:01.107058663Z 64 PC: 14431 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T22:38:01.117089672Z 66 PC: 14532 | Move file pointer
2018-12-17T22:38:01.119103655Z 64 PC: 144d3 | Write file or device (Write 6780 bytes on handle 6)
2018-12-17T22:38:01.129116379Z 62 PC: 14450 | Close file
2018-12-17T22:38:01.139859125Z 53 PC: 13698 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:01.143355274Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:01.145140343Z 53 PC: 13698 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:01.14825005Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:01.149939568Z 53 PC: 13698 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:01.151739916Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:01.1541614Z 53 PC: 13698 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:01.156105661Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:01.157644273Z 53 PC: 13698 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:01.15940178Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:01.161757249Z 53 PC: 13698 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:01.163341328Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:01.164872496Z 53 PC: 13698 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:01.167576315Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:01.169113445Z 53 PC: 13698 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:01.170684579Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:01.172997567Z 53 PC: 13698 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:01.174951146Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:01.176466624Z 53 PC: 13698 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:01.178774032Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:01.180614156Z 53 PC: 13698 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:01.182030567Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:01.183345857Z 53 PC: 13698 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:01.18537613Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:01.186831756Z 53 PC: 13698 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:01.188310074Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:01.190798545Z 53 PC: 13698 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:01.192284398Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:01.193758258Z 53 PC: 13698 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:01.196320268Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:01.197783167Z 53 PC: 13698 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:01.199261867Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:01.201707316Z 53 PC: 13698 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:01.203215701Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:01.2046835Z 53 PC: 13698 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:01.207038819Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:01.208829889Z 53 PC: 13698 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:01.210343404Z 37 PC: 136a1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:01.212980065Z 48 PC: 145c2 | Get DOS version
2018-12-17T22:38:01.215189949Z 41 PC: 1364f | Parse filename
2018-12-17T22:38:01.216935774Z 41 PC: 1365d | Parse filename
2018-12-17T22:38:01.219399518Z 75 PC: 13668 | Execute program
2018-12-17T22:38:01.243667367Z 80 PC: 1ac19 | Set current PSP
2018-12-17T22:38:01.244849435Z 48 PC: 1ac1e | Get DOS version
2018-12-17T22:38:01.24692799Z 99 PC: 21400 | Get DBCS lead byte table pointer
2018-12-17T22:38:01.250548003Z 101 PC: 1aca4 | Get extended country info
2018-12-17T22:38:01.252144134Z 99 PC: 1acaa | Get DBCS lead byte table pointer
2018-12-17T22:38:01.253750976Z 74 PC: 1ad0c | Reallocate memory
2018-12-17T22:38:01.256544504Z 25 PC: 1ad43 | Get default drive
2018-12-17T22:38:01.257990381Z 37 PC: 1a803 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:38:01.259458691Z 37 PC: 1a80a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:01.261984041Z 37 PC: 1a811 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:01.266323807Z 74 PC: 199ac | Reallocate memory
2018-12-17T22:38:01.268144193Z 72 PC: 199ed | Allocate memory
2018-12-17T22:38:01.271105238Z 72 PC: 19a25 | Allocate memory
2018-12-17T22:38:01.273204652Z 72 PC: 19a2d | Allocate memory