Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Edil.4992

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:30.701650029Z 53 PC: 13002 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:30.703982888Z 53 PC: 13002 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:30.705200595Z 53 PC: 13002 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:40:30.706340141Z 53 PC: 13002 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:30.708327699Z 53 PC: 13002 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:30.709302017Z 53 PC: 13002 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:30.710317261Z 53 PC: 13002 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:30.711684331Z 53 PC: 13002 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:30.712861181Z 53 PC: 13002 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:30.714026304Z 53 PC: 13002 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:30.715722856Z 53 PC: 13002 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:30.717417809Z 53 PC: 13002 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:30.718862735Z 53 PC: 13002 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:30.72029918Z 53 PC: 13002 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:30.723164436Z 53 PC: 13002 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:30.724469314Z 53 PC: 13002 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:30.725853171Z 53 PC: 13002 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:40:30.727796717Z 53 PC: 13002 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:40:30.729251713Z 53 PC: 13002 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:40:30.7307057Z 37 PC: 13017 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:30.732868146Z 37 PC: 1301f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:30.734724205Z 37 PC: 13027 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:30.736118975Z 37 PC: 1302f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:40:30.739409306Z 61 PC: 13596 | Open file (Filename = 'rom 1-Jun-1993.Eddie lives...somewhereU��F��')
2018-12-17T22:40:30.744928446Z 60 PC: 13596 | Create or truncate file
2018-12-17T22:40:30.749669449Z 48 PC: 13bde | Get DOS version
2018-12-17T22:40:30.751894465Z 61 PC: 13a04 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:40:30.758818936Z 63 PC: 13ad7 | Read file or device (Read 49152 bytes on handle 5)
2018-12-17T22:40:30.766746021Z 62 PC: 13a54 | Close file
2018-12-17T22:40:30.785225856Z 26 PC: 12eb5 | Set disk transfer address
2018-12-17T22:40:30.786736301Z 78 PC: 12ec1 | Find first file
2018-12-17T22:40:30.793343553Z 61 PC: 13a04 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:40:30.801222335Z 66 PC: 13ba0 | Move file pointer
2018-12-17T22:40:30.802734455Z 66 PC: 13bae | Move file pointer
2018-12-17T22:40:30.804055534Z 66 PC: 13bbc | Move file pointer
2018-12-17T22:40:30.813698614Z 62 PC: 13a54 | Close file
2018-12-17T22:40:30.815625813Z 61 PC: 13a04 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:40:30.8222535Z 63 PC: 13ad7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:40:30.824751968Z 62 PC: 13a54 | Close file
2018-12-17T22:40:30.826496695Z 26 PC: 12ed9 | Set disk transfer address
2018-12-17T22:40:30.827697181Z 79 PC: 12ede | Find next file
2018-12-17T22:40:30.830119799Z 48 PC: 13bde | Get DOS version
2018-12-17T22:40:30.831527729Z 61 PC: 13a04 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:40:30.838347625Z 66 PC: 13ba0 | Move file pointer
2018-12-17T22:40:30.840842972Z 66 PC: 13bae | Move file pointer
2018-12-17T22:40:30.842576864Z 66 PC: 13bbc | Move file pointer
2018-12-17T22:40:30.844492267Z 62 PC: 13a54 | Close file
2018-12-17T22:40:30.846535867Z 61 PC: 13a04 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:40:30.854051975Z 63 PC: 13ad7 | Read file or device (Read 4992 bytes on handle 5)
2018-12-17T22:40:30.861415208Z 63 PC: 13ad7 | Read file or device (Read 5120 bytes on handle 5)
2018-12-17T22:40:30.868708597Z 62 PC: 13a54 | Close file
2018-12-17T22:40:30.871371462Z 60 PC: 13a04 | Create or truncate file
2018-12-17T22:40:30.891496248Z 64 PC: 13ad7 | Write file or device (Write 5120 bytes on handle 5)
2018-12-17T22:40:30.900227548Z 62 PC: 13a54 | Close file
2018-12-17T22:40:30.909121522Z 48 PC: 13bde | Get DOS version
2018-12-17T22:40:30.910598286Z 41 PC: 12f6c | Parse filename
2018-12-17T22:40:30.912233106Z 41 PC: 12f7a | Parse filename
2018-12-17T22:40:30.914278574Z 75 PC: 12f85 | Execute program
2018-12-17T22:40:30.929055506Z 9 PC: 2528c | Display string (Could not find end pointer)
2018-12-17T22:40:30.934550875Z 76 PC: 25291 | Terminate with return code (Return code = '0')
2018-12-17T22:40:30.939016504Z 37 PC: 13116 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:30.940288598Z 37 PC: 13116 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:30.941638645Z 37 PC: 13116 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:40:30.943750435Z 37 PC: 13116 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:30.945101219Z 37 PC: 13116 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:30.946454288Z 37 PC: 13116 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:30.956233867Z 37 PC: 13116 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:30.957589819Z 37 PC: 13116 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:30.958928815Z 37 PC: 13116 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:30.961835576Z 37 PC: 13116 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:30.963527474Z 37 PC: 13116 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:30.964866912Z 37 PC: 13116 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:30.966926527Z 37 PC: 13116 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:30.969423219Z 37 PC: 13116 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:30.97123099Z 37 PC: 13116 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:30.982734775Z 37 PC: 13116 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:30.984568988Z 37 PC: 13116 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:40:30.98594042Z 37 PC: 13116 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:40:30.987467179Z 37 PC: 13116 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:40:30.989052343Z 76 PC: 13155 | Terminate with return code (Return code = '0')