Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Grosser

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:28.315761701Z 53 PC: 13eea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.318165392Z 53 PC: 13eea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.319660387Z 53 PC: 13eea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.32112421Z 53 PC: 13eea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.323622354Z 53 PC: 13eea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.325352138Z 53 PC: 13eea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.326827854Z 53 PC: 13eea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.335564144Z 53 PC: 13eea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.337046045Z 53 PC: 13eea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.338428623Z 53 PC: 13eea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.34004607Z 53 PC: 13eea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.343014595Z 53 PC: 13eea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.345216777Z 53 PC: 13eea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.347337481Z 53 PC: 13eea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.34979621Z 53 PC: 13eea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.35189808Z 53 PC: 13eea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.35400943Z 53 PC: 13eea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.364132332Z 53 PC: 13eea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.36522745Z 53 PC: 13eea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.366322042Z 37 PC: 13eff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.368853068Z 37 PC: 13f07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.369968154Z 37 PC: 13f0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.37104267Z 37 PC: 13f17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.373076332Z 68 PC: 148ea | I/O control for devices (Set for = '')
2018-12-17T21:57:28.394497026Z 37 PC: 13751 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.395779591Z 48 PC: 144fb | Get DOS version
2018-12-17T21:57:28.397856688Z 186 PC: 13e23 | UNKNOWN!
2018-12-17T21:57:28.399509351Z 61 PC: 143ad | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:28.403957356Z 63 PC: 14480 | Read file or device (Read 6380 bytes on handle 5)
2018-12-17T21:57:28.414121936Z 66 PC: 149e9 | Move file pointer
2018-12-17T21:57:28.41527565Z 66 PC: 149f7 | Move file pointer
2018-12-17T21:57:28.416518635Z 66 PC: 14a05 | Move file pointer
2018-12-17T21:57:28.418181182Z 66 PC: 144df | Move file pointer
2018-12-17T21:57:28.419253302Z 63 PC: 14480 | Read file or device (Read 6380 bytes on handle 5)
2018-12-17T21:57:28.42399573Z 66 PC: 149e9 | Move file pointer
2018-12-17T21:57:28.426701824Z 66 PC: 149f7 | Move file pointer
2018-12-17T21:57:28.428386285Z 66 PC: 14a05 | Move file pointer
2018-12-17T21:57:28.430153959Z 66 PC: 144df | Move file pointer
2018-12-17T21:57:28.433420463Z 64 PC: 143de | Write file or device (Write 0 bytes on handle 5)
2018-12-17T21:57:28.671464449Z 66 PC: 144df | Move file pointer
2018-12-17T21:57:28.673209198Z 64 PC: 14480 | Write file or device (Write 6380 bytes on handle 5)
2018-12-17T21:57:28.682250199Z 62 PC: 143fd | Close file
2018-12-17T21:57:28.696208431Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.697631616Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.699291363Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.700439002Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.701679578Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.716112322Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.718110865Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.71982901Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.722182102Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.724120178Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.726036654Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.729028912Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.731531899Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.733434692Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.735668021Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.737467971Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.73893357Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.741349684Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.742591637Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.743772016Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.745019899Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.746685833Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.748199322Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.749822237Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.751318478Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.752457213Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.753945987Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.755643878Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.756810885Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.758181483Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.759952765Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.761643544Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.763340077Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.76616817Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.767952511Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.769620043Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.771651492Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.772871678Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.774197796Z 41 PC: 13daf | Parse filename
2018-12-17T21:57:28.781320131Z 41 PC: 13dbd | Parse filename
2018-12-17T21:57:28.782786206Z 75 PC: 13dc8 | Execute program
2018-12-17T21:57:28.800834067Z 9 PC: 1cb5c | Display string (Could not find end pointer)
2018-12-17T21:57:28.80687351Z 76 PC: 1cb61 | Terminate with return code (Return code = '0')
2018-12-17T21:57:28.809806383Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.81086443Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.812399896Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.81351762Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.814494469Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.816206066Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.817556827Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.818674435Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.820453694Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.821724421Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.822931676Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.824544975Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.825678307Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.826887223Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.829346602Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.830615717Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.832889295Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.834916863Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.835939732Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.837448098Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.839180314Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.840371297Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.841602903Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.843198888Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.844223844Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.845267424Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.846889374Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.847897739Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.849157139Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.851148088Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.852095547Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.853203441Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.854897257Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.85590272Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.856854957Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.85858315Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.859547627Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.860414109Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.8655307Z 77 PC: 13de6 | Get program return code
2018-12-17T21:57:28.866692148Z 61 PC: 143ad | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:28.873962773Z 64 PC: 14480 | Write file or device (Write 6380 bytes on handle 5)
2018-12-17T21:57:28.879817602Z 66 PC: 149e9 | Move file pointer
2018-12-17T21:57:28.881130308Z 66 PC: 149f7 | Move file pointer
2018-12-17T21:57:28.882289569Z 66 PC: 14a05 | Move file pointer
2018-12-17T21:57:28.884141379Z 66 PC: 144df | Move file pointer
2018-12-17T21:57:28.885502484Z 64 PC: 14480 | Write file or device (Write 6380 bytes on handle 5)
2018-12-17T21:57:28.89376495Z 64 PC: 14480 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T21:57:28.897022931Z 62 PC: 143fd | Close file
2018-12-17T21:57:28.904994652Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.906151962Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:28.907295284Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.908142177Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:28.909371106Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.911635004Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:28.912568202Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.913949537Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:28.915650934Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.916793439Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:28.918233966Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.920225334Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:28.921379088Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.922762375Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:28.92453156Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.925730339Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:28.927168533Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.928423057Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:28.929775523Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.931452971Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:28.932831257Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.934071985Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:28.935690323Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.936819447Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:28.940905475Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.942764449Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:28.944059024Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.945251168Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:28.946886419Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.947939987Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:28.948929221Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.950337559Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:28.951589056Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.952788638Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:28.955980589Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.95723172Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:28.958385006Z 53 PC: 13e60 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.960168611Z 37 PC: 13e69 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:28.961774801Z 49 PC: 13e23 | Terminate and stay resident (Return code = '0' | Memory size = '2570')