Sample viewer

vx.netlux.org/Virus.DOS.HLLP.MF.6014

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:58.329021982Z 53 PC: 133ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:58.330679036Z 53 PC: 133ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:58.331987781Z 53 PC: 133ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:58.333193107Z 53 PC: 133ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:58.334446715Z 53 PC: 133ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:58.336721447Z 53 PC: 133ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:58.338131575Z 53 PC: 133ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:58.339463725Z 53 PC: 133ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:58.341383278Z 53 PC: 133ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:58.342940183Z 53 PC: 133ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:58.344450418Z 53 PC: 133ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:58.358667534Z 53 PC: 133ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:58.360504181Z 53 PC: 133ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:58.362283371Z 53 PC: 133ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:58.364300509Z 53 PC: 133ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:58.366387368Z 53 PC: 133ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:58.367761558Z 53 PC: 133ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:58.369899589Z 53 PC: 133ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:58.371387339Z 53 PC: 133ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:58.372735089Z 37 PC: 133ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:58.374032828Z 37 PC: 13407 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:58.376070096Z 37 PC: 1340f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:58.377359506Z 37 PC: 13417 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:58.379092384Z 68 PC: 13dea | I/O control for devices (Set for = '')
2018-12-17T22:39:58.381809328Z 48 PC: 139fb | Get DOS version
2018-12-17T22:39:58.384586002Z 26 PC: 13227 | Set disk transfer address
2018-12-17T22:39:58.386172515Z 78 PC: 13233 | Find first file
2018-12-17T22:39:58.393935845Z 61 PC: 138ad | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:39:58.401612057Z 66 PC: 13ee9 | Move file pointer
2018-12-17T22:39:58.403592255Z 66 PC: 13ef7 | Move file pointer
2018-12-17T22:39:58.4059893Z 66 PC: 13f05 | Move file pointer
2018-12-17T22:39:58.407966818Z 26 PC: 13227 | Set disk transfer address
2018-12-17T22:39:58.409496547Z 78 PC: 13233 | Find first file
2018-12-17T22:39:58.417712259Z 61 PC: 138ad | Open file (Filename = 'TEST.EXE')
2018-12-17T22:39:58.425589674Z 66 PC: 139df | Move file pointer
2018-12-17T22:39:58.427966683Z 63 PC: 1393f | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:39:58.436224414Z 63 PC: 1393f | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:39:58.439124768Z 63 PC: 1393f | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:39:58.441827639Z 62 PC: 138fd | Close file
2018-12-17T22:39:58.443669826Z 26 PC: 1324b | Set disk transfer address
2018-12-17T22:39:58.445237582Z 79 PC: 13250 | Find next file
2018-12-17T22:39:58.448796567Z 64 PC: 13808 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:39:58.451365133Z 37 PC: 13541 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:58.453403961Z 37 PC: 13541 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:58.45445797Z 37 PC: 13541 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:58.45550594Z 37 PC: 13541 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:58.457195453Z 37 PC: 13541 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:58.458741269Z 37 PC: 13541 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:58.465923576Z 37 PC: 13541 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:58.467928493Z 37 PC: 13541 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:58.47020638Z 37 PC: 13541 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:58.471806861Z 37 PC: 13541 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:58.473913749Z 37 PC: 13541 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:58.475395066Z 37 PC: 13541 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:58.476853691Z 37 PC: 13541 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:58.478763364Z 37 PC: 13541 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:58.480242579Z 37 PC: 13541 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:58.48168572Z 37 PC: 13541 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:58.4835836Z 37 PC: 13541 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:58.484975735Z 37 PC: 13541 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:58.486354066Z 37 PC: 13541 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:58.496243927Z 76 PC: 13580 | Terminate with return code (Return code = '0')