Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DNVG.5045.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:04.126028236Z 53 PC: 132ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:04.132613825Z 53 PC: 132ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:04.135409929Z 53 PC: 132ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:04.136483096Z 53 PC: 132ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:04.14371947Z 53 PC: 132ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:04.144830087Z 53 PC: 132ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:04.145892392Z 53 PC: 132ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:04.147476141Z 53 PC: 132ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:04.148768187Z 53 PC: 132ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:04.150347414Z 53 PC: 132ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:04.15251612Z 53 PC: 132ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:04.154046851Z 53 PC: 132ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:04.155343894Z 53 PC: 132ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:04.156845876Z 53 PC: 132ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:04.158663779Z 53 PC: 132ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:04.160282848Z 53 PC: 132ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:04.16198142Z 53 PC: 132ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:04.164393647Z 53 PC: 132ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:04.16566049Z 53 PC: 132ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:04.167289212Z 37 PC: 132ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:04.169691944Z 37 PC: 13307 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:04.171169739Z 37 PC: 1330f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:04.172713306Z 37 PC: 13317 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:04.175250954Z 68 PC: 13b7a | I/O control for devices (Set for = '')
2018-12-17T22:44:04.176965806Z 48 PC: 138a0 | Get DOS version
2018-12-17T22:44:04.178785125Z 48 PC: 138a0 | Get DOS version
2018-12-17T22:44:04.182427042Z 61 PC: 13752 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:44:04.189237139Z 63 PC: 13825 | Read file or device (Read 5040 bytes on handle 5)
2018-12-17T22:44:04.19572457Z 62 PC: 137a2 | Close file
2018-12-17T22:44:04.198497659Z 26 PC: 130ed | Set disk transfer address
2018-12-17T22:44:04.199648261Z 78 PC: 130f9 | Find first file
2018-12-17T22:44:04.204225829Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:44:04.205677091Z 79 PC: 13116 | Find next file
2018-12-17T22:44:04.208026402Z 48 PC: 138a0 | Get DOS version
2018-12-17T22:44:04.209688771Z 26 PC: 130ed | Set disk transfer address
2018-12-17T22:44:04.211577128Z 78 PC: 130f9 | Find first file
2018-12-17T22:44:04.218201414Z 48 PC: 138a0 | Get DOS version
2018-12-17T22:44:04.219744192Z 67 PC: 13076 | Get or set file attributes
2018-12-17T22:44:04.238136113Z 61 PC: 13752 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:44:04.24343101Z 66 PC: 13884 | Move file pointer
2018-12-17T22:44:04.244492786Z 63 PC: 13825 | Read file or device (Read 5040 bytes on handle 5)
2018-12-17T22:44:04.249917658Z 66 PC: 13884 | Move file pointer
2018-12-17T22:44:04.25096117Z 64 PC: 13783 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:44:04.258884304Z 66 PC: 13884 | Move file pointer
2018-12-17T22:44:04.261313154Z 64 PC: 13825 | Write file or device (Write 5040 bytes on handle 5)
2018-12-17T22:44:04.270229953Z 87 PC: 130bd | Get or set file date and time
2018-12-17T22:44:04.272123733Z 67 PC: 13076 | Get or set file attributes
2018-12-17T22:44:04.283647378Z 62 PC: 137a2 | Close file
2018-12-17T22:44:04.290500343Z 53 PC: 1325c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:04.291642735Z 37 PC: 13265 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:04.293486184Z 53 PC: 1325c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:04.295550364Z 37 PC: 13265 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:04.296995794Z 53 PC: 1325c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:04.298473605Z 37 PC: 13265 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:04.300225201Z 53 PC: 1325c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:04.301312887Z 37 PC: 13265 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:04.302364684Z 53 PC: 1325c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:04.303899264Z 37 PC: 13265 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:04.304920227Z 53 PC: 1325c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:04.305992041Z 37 PC: 13265 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:04.307771289Z 53 PC: 1325c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:04.30912864Z 37 PC: 13265 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:04.310440261Z 53 PC: 1325c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:04.313570625Z 37 PC: 13265 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:04.314674135Z 53 PC: 1325c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:04.31572016Z 37 PC: 13265 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:04.31733031Z 53 PC: 1325c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:04.318662647Z 37 PC: 13265 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:04.319887071Z 53 PC: 1325c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:04.32210603Z 37 PC: 13265 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:04.323172335Z 53 PC: 1325c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:04.324284287Z 37 PC: 13265 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:04.326543433Z 53 PC: 1325c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:04.328259826Z 37 PC: 13265 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:04.329830243Z 53 PC: 1325c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:04.33186988Z 37 PC: 13265 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:04.333094073Z 53 PC: 1325c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:04.334342121Z 37 PC: 13265 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:04.343534217Z 53 PC: 1325c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:04.344668776Z 37 PC: 13265 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:04.34582633Z 53 PC: 1325c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:04.347773168Z 37 PC: 13265 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:04.348883433Z 53 PC: 1325c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:04.350025124Z 37 PC: 13265 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:04.352034947Z 53 PC: 1325c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:04.353179381Z 37 PC: 13265 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:04.35489204Z 41 PC: 13213 | Parse filename
2018-12-17T22:44:04.356980254Z 41 PC: 13221 | Parse filename
2018-12-17T22:44:04.358433005Z 75 PC: 1322c | Execute program
2018-12-17T22:44:04.379164322Z 80 PC: 18859 | Set current PSP
2018-12-17T22:44:04.380499969Z 48 PC: 1885e | Get DOS version
2018-12-17T22:44:04.381912776Z 99 PC: 1f040 | Get DBCS lead byte table pointer
2018-12-17T22:44:04.384518786Z 101 PC: 188e4 | Get extended country info
2018-12-17T22:44:04.386561673Z 99 PC: 188ea | Get DBCS lead byte table pointer
2018-12-17T22:44:04.387649484Z 74 PC: 1894c | Reallocate memory
2018-12-17T22:44:04.389082119Z 25 PC: 18983 | Get default drive
2018-12-17T22:44:04.390606684Z 37 PC: 18443 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:44:04.392310033Z 37 PC: 1844a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:04.393215443Z 37 PC: 18451 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:04.397783468Z 74 PC: 175ec | Reallocate memory
2018-12-17T22:44:04.399185769Z 72 PC: 1762d | Allocate memory
2018-12-17T22:44:04.400674876Z 72 PC: 17665 | Allocate memory
2018-12-17T22:44:04.402708227Z 72 PC: 1766d | Allocate memory