Sample viewer

vx.netlux.org/Virus.DOS.HLLP.PPZ.8586

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:39.423745494Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:39.425439939Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:39.428060868Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:39.429756886Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:39.430950843Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:39.431933248Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:39.433749889Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:39.435026195Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:39.436104828Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:39.437737114Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:39.438789502Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:39.439763973Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:39.44202238Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:39.443006754Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:39.444469627Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:39.447311696Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:39.448578534Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:39.466892294Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:39.486831032Z 53 PC: 14f6a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:39.488429564Z 37 PC: 14f7f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:39.489913612Z 37 PC: 14f87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:39.492340784Z 37 PC: 14f8f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:39.493787228Z 37 PC: 14f97 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:39.495647656Z 68 PC: 15acc | I/O control for devices (Set for = '')
2018-12-17T22:41:39.537572223Z 37 PC: 14681 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:39.539337063Z 48 PC: 157f2 | Get DOS version
2018-12-17T22:41:39.541081089Z 53 PC: 14da1 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:41:39.543525955Z 37 PC: 14dbd | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:41:39.545410582Z 53 PC: 14da1 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:41:39.546951999Z 37 PC: 14dbd | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:41:39.550696746Z 53 PC: 14da1 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:39.552202528Z 37 PC: 14dbd | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:39.55557541Z 51 PC: 14c8f | Get or set Ctrl-Break
2018-12-17T22:41:39.557788151Z 60 PC: 15630 | Create or truncate file
2018-12-17T22:41:39.577680634Z 65 PC: 15779 | Delete file (Filename = '/�')
2018-12-17T22:41:39.588546635Z 48 PC: 157f2 | Get DOS version
2018-12-17T22:41:39.590400321Z 61 PC: 15630 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:41:39.598490839Z 66 PC: 15762 | Move file pointer
2018-12-17T22:41:39.600286949Z 63 PC: 15703 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:41:39.607424758Z 62 PC: 15680 | Close file
2018-12-17T22:41:39.614926491Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:39.616402309Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:39.618374471Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:39.620851721Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:39.622307012Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:39.623750152Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:39.626078323Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:39.627907283Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:39.629349062Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:39.631450582Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:39.633204771Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:39.634639553Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:39.636729757Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:39.638488317Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:39.639887704Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:39.641480456Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:39.64364491Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:39.645041411Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:39.647084402Z 37 PC: 150c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:39.650141701Z 76 PC: 15100 | Terminate with return code (Return code = '8')