Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Harmless.6144

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:06.836401554Z 53 PC: 1349a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:06.842240702Z 53 PC: 1349a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:06.846804654Z 53 PC: 1349a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:40:06.847996322Z 53 PC: 1349a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:06.85005041Z 53 PC: 1349a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:06.853038362Z 53 PC: 1349a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:06.854151914Z 53 PC: 1349a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:06.855750005Z 53 PC: 1349a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:06.857649664Z 53 PC: 1349a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:06.859680027Z 53 PC: 1349a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:06.860827132Z 53 PC: 1349a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:06.863102345Z 53 PC: 1349a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:06.864435439Z 53 PC: 1349a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:06.865684605Z 53 PC: 1349a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:06.869391578Z 53 PC: 1349a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:06.871757351Z 53 PC: 1349a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:06.873345354Z 53 PC: 1349a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:40:06.875058982Z 53 PC: 1349a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:40:06.878167681Z 53 PC: 1349a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:40:06.879729504Z 37 PC: 134af | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:06.881056837Z 37 PC: 134b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:06.883983364Z 37 PC: 134bf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:06.88656863Z 37 PC: 134c7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:40:06.892701148Z 68 PC: 13e95 | I/O control for devices (Set for = '')
2018-12-17T22:40:06.897014019Z 44 PC: 13fcc | Get time 0x13fcc: mov word ptr [0x3e], cx
0x13fd0: mov word ptr [0x40], dx
0x13fd4: retf
0x13fd5: call 0x1401c
0x13fd8: jb 0x13fe9
0x13fda: mov cx, word ptr es:[di + 4]
0x13fde: cmp cx, 1
0x13fe1: je 0x13fe9
0x13fe3: xor bx, bx
0x13fe5: push cs
0x13fe6: call 0x23b5d
0x13fe9: retf 4
0x13fec: call 0x1401c
0x13fef: jb 0x14004
0x13ff1: mov ax, cx
0x13ff3: mov dx, bx
0x13ff5: mov cx, word ptr es:[di + 4]
0x13ff9: cmp cx, 1
0x13ffc: je 0x14004
0x13ffe: xor bx, bx
2018-12-17T22:40:06.900589685Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.902490075Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.912095045Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.913855862Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.91657022Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.919038276Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.922810922Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.924264191Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.927092333Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.929343031Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.931769548Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.935579775Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.952444622Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.953847717Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.956821422Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.962738716Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.965622753Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.967426711Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.97100419Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.972944505Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.9755403Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.977906084Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.980538188Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.981996677Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.985041886Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.986444811Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.988959775Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.990897866Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.99322157Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:06.994575834Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:06.997181147Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.000848014Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.003060029Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.004192476Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.007610005Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.009587339Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.011927695Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.014190154Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.016791229Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.018274485Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.021507428Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.022905544Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.025312886Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.027082549Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.029618162Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.031051394Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.034247687Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.03531971Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.038403673Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.040140075Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.045158661Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.046848986Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.051512164Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.053162053Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.057381789Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.05942722Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.063895382Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.065893485Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.069937641Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.072292495Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.075737345Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.077441255Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.081078647Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.082631954Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.086302679Z 26 PC: 132cd | Set disk transfer address
2018-12-17T22:40:07.088742201Z 78 PC: 132d9 | Find first file
2018-12-17T22:40:07.105670727Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.107000434Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.111115323Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.112510543Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.115933363Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.117660396Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.121085259Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.122460883Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.126657946Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.127859122Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.134734966Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.137193554Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.141141199Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.14243038Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.147217081Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.148455247Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.151887673Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.153391948Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.158364518Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.159891446Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.163623306Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.165531771Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.170019319Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.171455636Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.175717602Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.177214954Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.180992019Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.183567616Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.187342826Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.188848224Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.19641667Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.197940011Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.201688411Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.203957022Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.20800239Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.209481939Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.213381955Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.21562635Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.219372786Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.220893413Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.225244105Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.226726419Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.230432309Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.232916405Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.236892383Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.238411546Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.247217495Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.248720909Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.251558319Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.253184934Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.255843538Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.256849918Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.260030802Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.261091123Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.263784422Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.265466682Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.268077215Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.269038942Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.275094425Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.27632702Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.282938158Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.28540948Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.292301705Z 26 PC: 132f1 | Set disk transfer address
2018-12-17T22:40:07.293717944Z 79 PC: 132f6 | Find next file
2018-12-17T22:40:07.30215924Z 48 PC: 13aab | Get DOS version
2018-12-17T22:40:07.30416127Z 67 PC: 1322f | Get or set file attributes
2018-12-17T22:40:07.310559397Z 67 PC: 13256 | Get or set file attributes
2018-12-17T22:40:07.330201299Z 61 PC: 1395d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:40:07.340752036Z 87 PC: 13270 | Get or set file date and time
2018-12-17T22:40:07.342370245Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.344772918Z 63 PC: 13a30 | Read file or device (Read 6144 bytes on handle 5)
2018-12-17T22:40:07.35235015Z 66 PC: 14036 | Move file pointer
2018-12-17T22:40:07.353855778Z 66 PC: 14044 | Move file pointer
2018-12-17T22:40:07.356059297Z 66 PC: 14052 | Move file pointer
2018-12-17T22:40:07.358115369Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.359781859Z 63 PC: 13a30 | Read file or device (Read 6144 bytes on handle 5)
2018-12-17T22:40:07.367569426Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.36924911Z 64 PC: 13a30 | Write file or device (Write 5120 bytes on handle 5)
2018-12-17T22:40:07.377340879Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.379350583Z 64 PC: 1398e | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:40:07.390010836Z 87 PC: 1329d | Get or set file date and time
2018-12-17T22:40:07.392737057Z 62 PC: 139ad | Close file
2018-12-17T22:40:07.401975839Z 67 PC: 13256 | Get or set file attributes
2018-12-17T22:40:07.417190806Z 41 PC: 13401 | Parse filename
2018-12-17T22:40:07.420667376Z 41 PC: 1340f | Parse filename
2018-12-17T22:40:07.424547234Z 75 PC: 1341a | Execute program
2018-12-17T22:40:07.441280163Z 9 PC: 176bc | Display string (Could not find end pointer)
2018-12-17T22:40:07.446856966Z 76 PC: 176c1 | Terminate with return code (Return code = '0')
2018-12-17T22:40:07.455609476Z 67 PC: 1322f | Get or set file attributes
2018-12-17T22:40:07.461757413Z 67 PC: 13256 | Get or set file attributes
2018-12-17T22:40:07.47217001Z 61 PC: 1395d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:40:07.480192409Z 87 PC: 13270 | Get or set file date and time
2018-12-17T22:40:07.482310707Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.484342945Z 63 PC: 13a30 | Read file or device (Read 6144 bytes on handle 5)
2018-12-17T22:40:07.492638565Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.494623684Z 64 PC: 13a30 | Write file or device (Write 6144 bytes on handle 5)
2018-12-17T22:40:07.501924587Z 66 PC: 14036 | Move file pointer
2018-12-17T22:40:07.503889648Z 66 PC: 14044 | Move file pointer
2018-12-17T22:40:07.505276332Z 66 PC: 14052 | Move file pointer
2018-12-17T22:40:07.506645924Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.50856536Z 64 PC: 13a30 | Write file or device (Write 5120 bytes on handle 5)
2018-12-17T22:40:07.515288869Z 87 PC: 1329d | Get or set file date and time
2018-12-17T22:40:07.516723203Z 62 PC: 139ad | Close file
2018-12-17T22:40:07.523409521Z 67 PC: 13256 | Get or set file attributes
2018-12-17T22:40:07.531230791Z 67 PC: 1322f | Get or set file attributes
2018-12-17T22:40:07.536239899Z 67 PC: 13256 | Get or set file attributes
2018-12-17T22:40:07.885130119Z 61 PC: 1395d | Open file (Filename = 'C:\WINDOWS\SETUP.EXE')
2018-12-17T22:40:07.893485623Z 87 PC: 13270 | Get or set file date and time
2018-12-17T22:40:07.895422521Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.89747166Z 63 PC: 13a30 | Read file or device (Read 6144 bytes on handle 5)
2018-12-17T22:40:07.93304239Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:07.935674804Z 64 PC: 13a30 | Write file or device (Write 6144 bytes on handle 5)
2018-12-17T22:40:08.27314793Z 66 PC: 14036 | Move file pointer
2018-12-17T22:40:08.275513794Z 66 PC: 14044 | Move file pointer
2018-12-17T22:40:08.27721535Z 66 PC: 14052 | Move file pointer
2018-12-17T22:40:08.278992798Z 66 PC: 13a8f | Move file pointer
2018-12-17T22:40:08.28172531Z 64 PC: 13a30 | Write file or device (Write 6144 bytes on handle 5)
2018-12-17T22:40:08.306020092Z 87 PC: 1329d | Get or set file date and time
2018-12-17T22:40:08.307670221Z 62 PC: 139ad | Close file
2018-12-17T22:40:08.315997402Z 67 PC: 13256 | Get or set file attributes
2018-12-17T22:40:08.326560952Z 77 PC: 13438 | Get program return code
2018-12-17T22:40:08.328105914Z 64 PC: 138b8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:40:08.33101581Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:08.332269675Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:08.333525203Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:40:08.335680021Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:08.336885304Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:08.33809684Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:08.340286612Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:08.341506744Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:08.342740271Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:08.344914495Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:08.346197605Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:08.347512725Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:08.349731743Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:08.350990968Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:08.352113807Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:08.353429859Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:08.355230531Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:40:08.356744584Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:40:08.358291099Z 37 PC: 135f1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:40:08.359910461Z 76 PC: 13630 | Terminate with return code (Return code = '0')