Sample viewer

vx.netlux.org/Virus.DOS.HLLP.ArchVir.5070

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:43.581114485Z 53 PC: 13522 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:43.583637173Z 53 PC: 13522 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:43.585145767Z 53 PC: 13522 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:43.586555003Z 53 PC: 13522 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:43.590953133Z 53 PC: 13522 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:43.593263593Z 53 PC: 13522 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:43.595005905Z 53 PC: 13522 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:43.596715627Z 53 PC: 13522 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:43.599117618Z 53 PC: 13522 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:43.6011792Z 53 PC: 13522 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:43.602739841Z 53 PC: 13522 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:43.605409104Z 53 PC: 13522 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:43.60715861Z 53 PC: 13522 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:43.60889448Z 53 PC: 13522 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:43.611248752Z 53 PC: 13522 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:43.612631909Z 53 PC: 13522 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:43.614012392Z 53 PC: 13522 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:43.623913809Z 53 PC: 13522 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:43.625481353Z 53 PC: 13522 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:43.627073273Z 37 PC: 13537 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:43.629419199Z 37 PC: 1353f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:43.630698662Z 37 PC: 13547 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:43.632166859Z 37 PC: 1354f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:43.63496772Z 68 PC: 13b22 | I/O control for devices (Set for = '')
2018-12-17T22:44:43.636908795Z 25 PC: 14244 | Get default drive
2018-12-17T22:44:43.638293055Z 71 PC: 14257 | Get current directory
2018-12-17T22:44:43.642952737Z 48 PC: 141b7 | Get DOS version
2018-12-17T22:44:43.64544104Z 61 PC: 13f77 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:44:43.653180115Z 63 PC: 1404a | Read file or device (Read 5070 bytes on handle 5)
2018-12-17T22:44:43.66148288Z 66 PC: 140a9 | Move file pointer
2018-12-17T22:44:43.66426233Z 66 PC: 14113 | Move file pointer
2018-12-17T22:44:43.665885197Z 66 PC: 14121 | Move file pointer
2018-12-17T22:44:43.667769717Z 66 PC: 1412f | Move file pointer
2018-12-17T22:44:43.670446284Z 63 PC: 1404a | Read file or device (Read 2034 bytes on handle 5)
2018-12-17T22:44:43.67864378Z 60 PC: 13f77 | Create or truncate file
2018-12-17T22:44:43.695877497Z 64 PC: 1404a | Write file or device (Write 2034 bytes on handle 6)
2018-12-17T22:44:43.706174758Z 62 PC: 13fc7 | Close file
2018-12-17T22:44:43.712622797Z 62 PC: 13fc7 | Close file
2018-12-17T22:44:43.733134762Z 53 PC: 1333c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:43.735526624Z 37 PC: 13345 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:44:43.737440048Z 53 PC: 1333c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:43.73903313Z 37 PC: 13345 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:44:43.740739425Z 53 PC: 1333c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:43.743152066Z 37 PC: 13345 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:44:43.744698921Z 53 PC: 1333c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:43.746273589Z 37 PC: 13345 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:43.748801587Z 53 PC: 1333c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:43.750404398Z 37 PC: 13345 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:43.751950501Z 53 PC: 1333c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:43.754568518Z 37 PC: 13345 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:43.756143075Z 53 PC: 1333c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:43.757696863Z 37 PC: 13345 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:44:43.760171301Z 53 PC: 1333c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:43.762046263Z 37 PC: 13345 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:44:43.763595823Z 53 PC: 1333c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:43.765403418Z 37 PC: 13345 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:44:43.767378587Z 53 PC: 1333c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:43.76906823Z 37 PC: 13345 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:44:43.770721175Z 53 PC: 1333c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:43.773431165Z 37 PC: 13345 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:44:43.775194407Z 53 PC: 1333c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:43.776902264Z 37 PC: 13345 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:44:43.779637091Z 53 PC: 1333c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:43.781321675Z 37 PC: 13345 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:44:43.78306027Z 53 PC: 1333c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:43.785612734Z 37 PC: 13345 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:44:43.789346226Z 53 PC: 1333c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:43.791133543Z 37 PC: 13345 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:44:43.793673243Z 53 PC: 1333c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:43.795124579Z 37 PC: 13345 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:44:43.79634443Z 53 PC: 1333c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:43.797935708Z 37 PC: 13345 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:44:43.799894527Z 53 PC: 1333c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:43.801549275Z 37 PC: 13345 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:44:43.803890943Z 53 PC: 1333c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:43.80599742Z 37 PC: 13345 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:44:43.807831424Z 41 PC: 133c5 | Parse filename
2018-12-17T22:44:43.809464211Z 41 PC: 133d3 | Parse filename
2018-12-17T22:44:43.811714026Z 75 PC: 133de | Execute program
2018-12-17T22:44:43.836343604Z 80 PC: 61be9 | Set current PSP
2018-12-17T22:44:43.837627776Z 48 PC: 61bee | Get DOS version
2018-12-17T22:44:43.840698453Z 99 PC: 683d0 | Get DBCS lead byte table pointer
2018-12-17T22:44:43.843804737Z 101 PC: 61c74 | Get extended country info
2018-12-17T22:44:43.845507625Z 99 PC: 61c7a | Get DBCS lead byte table pointer
2018-12-17T22:44:43.848255877Z 74 PC: 61cdc | Reallocate memory
2018-12-17T22:44:43.850070676Z 25 PC: 61d13 | Get default drive
2018-12-17T22:44:43.851581744Z 37 PC: 617d3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:44:43.85366138Z 37 PC: 617da | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:44:43.855542052Z 37 PC: 617e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:43.860160255Z 74 PC: 6097c | Reallocate memory
2018-12-17T22:44:43.862681661Z 72 PC: 609bd | Allocate memory
2018-12-17T22:44:43.86505577Z 72 PC: 609f5 | Allocate memory
2018-12-17T22:44:43.867219624Z 72 PC: 609fd | Allocate memory