Sample viewer

vx.netlux.org/Virus.DOS.HLLP.WarmBoot.4940

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:15.247751667Z 53 PC: 136ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:15.249550422Z 53 PC: 136ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:15.252104768Z 53 PC: 136ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:15.253275477Z 53 PC: 136ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:15.25503269Z 53 PC: 136ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:15.265298198Z 53 PC: 136ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:15.266706049Z 53 PC: 136ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:15.268068059Z 53 PC: 136ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:15.270072225Z 53 PC: 136ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:15.272551745Z 53 PC: 136ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:15.275820903Z 53 PC: 136ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:15.278822476Z 53 PC: 136ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:15.286384559Z 53 PC: 136ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:15.287634657Z 53 PC: 136ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:15.288812516Z 53 PC: 136ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:15.290673722Z 53 PC: 136ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:15.292505653Z 53 PC: 136ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:15.2943418Z 53 PC: 136ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:15.296948011Z 53 PC: 136ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:15.29860169Z 37 PC: 136cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:15.30010644Z 37 PC: 136d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:15.302108396Z 37 PC: 136df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:15.303418588Z 37 PC: 136e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:15.304997449Z 68 PC: 141a8 | I/O control for devices (Set for = '')
2018-12-17T22:43:15.307538217Z 64 PC: 13ad8 | Write file or device (Write 79 bytes on handle 1)
2018-12-17T22:43:15.322514237Z 64 PC: 13ad8 | Write file or device (Write 18 bytes on handle 1)
2018-12-17T22:43:15.325709123Z 64 PC: 13ad8 | Write file or device (Write 16 bytes on handle 1)
2018-12-17T22:43:15.337547512Z 250 PC: 13260 | UNKNOWN!
2018-12-17T22:43:15.3393314Z 48 PC: 13ece | Get DOS version
2018-12-17T22:43:15.341097858Z 61 PC: 13d80 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:43:15.362267206Z 66 PC: 13eb2 | Move file pointer
2018-12-17T22:43:15.365227881Z 63 PC: 13e53 | Read file or device (Read 4940 bytes on handle 5)
2018-12-17T22:43:15.383455933Z 62 PC: 13dd0 | Close file
2018-12-17T22:43:15.385928422Z 53 PC: 1362b | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:15.388077762Z 37 PC: 13634 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:15.389402943Z 53 PC: 1362b | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:15.390694586Z 37 PC: 13634 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:15.392598834Z 53 PC: 1362b | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:15.394104949Z 37 PC: 13634 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:15.395690016Z 53 PC: 1362b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:15.397945069Z 37 PC: 13634 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:15.399436321Z 53 PC: 1362b | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:15.401035408Z 37 PC: 13634 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:15.4033857Z 53 PC: 1362b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:15.404974489Z 37 PC: 13634 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:15.406432882Z 53 PC: 1362b | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:15.40866144Z 37 PC: 13634 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:15.410276742Z 53 PC: 1362b | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:15.412216749Z 37 PC: 13634 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:15.41412224Z 53 PC: 1362b | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:15.416952615Z 37 PC: 13634 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:15.418772038Z 53 PC: 1362b | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:15.420630583Z 37 PC: 13634 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:15.42356569Z 53 PC: 1362b | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:15.425588671Z 37 PC: 13634 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:15.427398632Z 53 PC: 1362b | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:15.430334579Z 37 PC: 13634 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:15.431797294Z 53 PC: 1362b | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:15.43368053Z 37 PC: 13634 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:15.435325273Z 53 PC: 1362b | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:15.437187724Z 37 PC: 13634 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:15.438623917Z 53 PC: 1362b | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:15.440080382Z 37 PC: 13634 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:15.441863866Z 53 PC: 1362b | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:15.44332946Z 37 PC: 13634 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:15.444739653Z 53 PC: 1362b | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:15.447050743Z 37 PC: 13634 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:15.448706003Z 53 PC: 1362b | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:15.450496378Z 37 PC: 13634 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:15.45278448Z 53 PC: 1362b | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:15.455059749Z 37 PC: 13634 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:15.456411074Z 53 PC: 134de | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:43:15.458738958Z 53 PC: 134de | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:15.460257101Z 37 PC: 134fa | Set interrupt vector (Interrupt = '228' AKA 'UNKNOWN!')
2018-12-17T22:43:15.461610839Z 37 PC: 134fa | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:43:15.463913334Z 37 PC: 134fa | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:15.465321222Z 37 PC: 12f5e | Set interrupt vector (Interrupt = '229' AKA 'UNKNOWN!')
2018-12-17T22:43:15.466882496Z 98 PC: 12f5e | Get current PSP
2018-12-17T22:43:15.468349135Z 49 PC: 12f5e | Terminate and stay resident (Return code = '0' | Memory size = '1397')