Sample viewer

vx.netlux.org/Virus.DOS.HLLP.4449

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:01.158367748Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:01.161052545Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:01.163959588Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:01.165692918Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:01.16743065Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:01.170275359Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:01.171984356Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:01.173705229Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:01.178148928Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:01.179876506Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:01.18157778Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:01.199972177Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:01.201759457Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:01.210485836Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:01.212058028Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:01.213969317Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:01.215680143Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:01.217369092Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:01.221718852Z 53 PC: 12e6a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:01.224086435Z 37 PC: 12e7f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:01.226142078Z 37 PC: 12e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:01.238792462Z 37 PC: 12e8f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:01.240101027Z 37 PC: 12e97 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:01.24182788Z 68 PC: 13750 | I/O control for devices (Set for = '')
2018-12-17T22:44:01.244198496Z 48 PC: 1347b | Get DOS version
2018-12-17T22:44:01.245870257Z 48 PC: 1347b | Get DOS version
2018-12-17T22:44:01.247653565Z 61 PC: 1332d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:44:01.255648994Z 63 PC: 13400 | Read file or device (Read 4444 bytes on handle 5)
2018-12-17T22:44:01.264146451Z 62 PC: 1337d | Close file
2018-12-17T22:44:01.266696272Z 26 PC: 12db7 | Set disk transfer address
2018-12-17T22:44:01.269160885Z 78 PC: 12dc3 | Find first file
2018-12-17T22:44:01.278162223Z 26 PC: 12ddb | Set disk transfer address
2018-12-17T22:44:01.280191716Z 79 PC: 12de0 | Find next file
2018-12-17T22:44:01.285943993Z 64 PC: 13288 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:44:01.288515284Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:01.29021685Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:01.291891634Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:01.294615509Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:01.296507556Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:01.298477348Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:01.300512411Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:01.302102737Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:01.303875544Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:01.306405293Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:01.308059069Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:01.309637949Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:01.326374725Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:01.328162624Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:01.329840553Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:01.332215371Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:01.33408601Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:01.335720017Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:01.337928173Z 37 PC: 12fc1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:01.339578723Z 76 PC: 13000 | Terminate with return code (Return code = '0')