Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Feci.7000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:39.711130505Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:39.713822358Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:42:39.715438142Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:42:39.71789462Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:39.719414131Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:39.720760089Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:39.723485515Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:42:39.724593302Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:42:39.725932924Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:42:39.72781702Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:42:39.729237582Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:42:39.730664932Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:42:39.732795893Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:42:39.734941722Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:42:39.736483455Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:42:39.738093179Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:42:39.739463592Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:42:39.741114291Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:42:39.742614115Z 53 PC: 13e2a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:42:39.744079641Z 37 PC: 13e3f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:39.746001843Z 37 PC: 13e47 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:39.758180537Z 37 PC: 13e4f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:39.75947526Z 37 PC: 13e57 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:42:39.762073748Z 68 PC: 14b32 | I/O control for devices (Set for = '')
2018-12-17T22:42:39.7635258Z 48 PC: 14743 | Get DOS version
2018-12-17T22:42:39.765192763Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:39.787190294Z 42 PC: 13c17 | Get date 0x13c17: xor ah, ah
0x13c19: les di, ptr [bp + 6]
0x13c1c: stosw word ptr es:[di], ax
0x13c1d: mov al, dl
0x13c1f: les di, ptr [bp + 0xa]
0x13c22: stosw word ptr es:[di], ax
0x13c23: mov al, dh
0x13c25: les di, ptr [bp + 0xe]
0x13c28: stosw word ptr es:[di], ax
0x13c29: xchg ax, cx
0x13c2a: les di, ptr [bp + 0x12]
0x13c2d: stosw word ptr es:[di], ax
0x13c2e: pop bp
0x13c2f: retf 0x10
0x13c32: push bp
0x13c33: mov bp, sp
0x13c35: mov cx, word ptr [bp + 0xa]
0x13c38: mov dh, byte ptr [bp + 8]
0x13c3b: mov dl, byte ptr [bp + 6]
0x13c3e: mov ah, 0x2b
2018-12-17T22:42:39.789837133Z 61 PC: 14581 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:42:39.797375211Z 66 PC: 146b3 | Move file pointer
2018-12-17T22:42:39.798979883Z 63 PC: 14654 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:42:39.816246719Z 62 PC: 145d1 | Close file
2018-12-17T22:42:39.819407654Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:40.199814298Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:40.203465847Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:40.586899949Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:40.59049595Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:40.934328831Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:40.93898874Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:41.304980315Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:41.309915613Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:41.63794011Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:41.641524346Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:42.009596224Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:42.020201764Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:42.356344493Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:42.360548405Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:42.703201008Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:42.706409003Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:43.075543204Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:43.078604679Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:43.406106881Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:43.409258743Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:43.792101218Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:43.795778909Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:44.12426382Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:44.134706219Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:44.491912504Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:44.494858029Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:44.89655761Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:44.901162086Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:45.338189522Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:45.341766156Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:45.779515243Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:45.782918247Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:46.22132905Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:46.231264147Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:46.552195697Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:46.556211308Z 54 PC: 13c8c | Get free disk space
2018-12-17T22:42:46.925364771Z 54 PC: 13ca5 | Get free disk space
2018-12-17T22:42:46.928839782Z 64 PC: 14248 | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:42:46.932482552Z 64 PC: 14248 | Write file or device (Write 8 bytes on handle 1)
2018-12-17T22:42:46.935793094Z 64 PC: 14248 | Write file or device (Write 14 bytes on handle 1)
2018-12-17T22:42:46.941247863Z 64 PC: 14248 | Write file or device (Write 10 bytes on handle 1)
2018-12-17T22:42:46.945117056Z 64 PC: 14248 | Write file or device (Write 17 bytes on handle 1)
2018-12-17T22:42:46.949188128Z 1 PC: 134d6 | Character input