Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5536

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:52.411382583Z 53 PC: 12eca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:52.41342895Z 53 PC: 12eca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:52.419948918Z 53 PC: 12eca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:52.421331062Z 53 PC: 12eca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:52.423124066Z 53 PC: 12eca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:52.436282604Z 53 PC: 12eca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:52.442870488Z 53 PC: 12eca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:52.444898778Z 53 PC: 12eca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:52.447662451Z 53 PC: 12eca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:52.449165064Z 53 PC: 12eca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:52.450800576Z 53 PC: 12eca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:52.456951911Z 53 PC: 12eca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:52.458632019Z 53 PC: 12eca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:52.46086078Z 53 PC: 12eca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:52.477938247Z 53 PC: 12eca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:52.480036292Z 53 PC: 12eca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:52.482375662Z 53 PC: 12eca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:52.485156335Z 53 PC: 12eca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:52.488419731Z 53 PC: 12eca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:52.490818479Z 37 PC: 12edf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:52.492209923Z 37 PC: 12ee7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:52.495211197Z 37 PC: 12eef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:52.49731857Z 37 PC: 12ef7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:52.499385046Z 68 PC: 13d30 | I/O control for devices (Set for = '')
2018-12-17T22:45:52.511006831Z 26 PC: 12e17 | Set disk transfer address
2018-12-17T22:45:52.512428192Z 78 PC: 12e23 | Find first file
2018-12-17T22:45:52.519367495Z 26 PC: 12e3b | Set disk transfer address
2018-12-17T22:45:52.521552344Z 79 PC: 12e40 | Find next file
2018-12-17T22:45:52.524878073Z 67 PC: 12de6 | Get or set file attributes
2018-12-17T22:45:52.543073649Z 61 PC: 137f3 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:45:52.553126077Z 63 PC: 138c6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:45:52.560957536Z 62 PC: 13843 | Close file
2018-12-17T22:45:52.563731725Z 48 PC: 13941 | Get DOS version
2018-12-17T22:45:52.565761259Z 61 PC: 137f3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:45:52.574658398Z 63 PC: 138c6 | Read file or device (Read 5536 bytes on handle 5)
2018-12-17T22:45:52.584739774Z 62 PC: 13843 | Close file
2018-12-17T22:45:52.587214602Z 61 PC: 137f3 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:45:52.595781005Z 66 PC: 13e2f | Move file pointer
2018-12-17T22:45:52.597296886Z 66 PC: 13e3d | Move file pointer
2018-12-17T22:45:52.598819322Z 66 PC: 13e4b | Move file pointer
2018-12-17T22:45:52.601347192Z 63 PC: 138c6 | Read file or device (Read 27 bytes on handle 5)
2018-12-17T22:45:52.609210608Z 66 PC: 13925 | Move file pointer
2018-12-17T22:45:52.611019892Z 64 PC: 138c6 | Write file or device (Write 5536 bytes on handle 5)
2018-12-17T22:45:52.634408731Z 64 PC: 138c6 | Write file or device (Write 27 bytes on handle 5)
2018-12-17T22:45:52.637733168Z 62 PC: 13843 | Close file
2018-12-17T22:45:52.657987291Z 64 PC: 1354b | Write file or device (Write 63 bytes on handle 1)
2018-12-17T22:45:52.679601501Z 64 PC: 1354b | Write file or device (Write 63 bytes on handle 1)
2018-12-17T22:45:52.6872676Z 64 PC: 1354b | Write file or device (Write 44 bytes on handle 1)
2018-12-17T22:45:52.693502111Z 64 PC: 1354b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:45:52.696884405Z 37 PC: 13021 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:52.698980213Z 37 PC: 13021 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:52.700760954Z 37 PC: 13021 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:52.703294841Z 37 PC: 13021 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:52.705370258Z 37 PC: 13021 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:52.707951002Z 37 PC: 13021 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:52.709675773Z 37 PC: 13021 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:52.711528512Z 37 PC: 13021 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:52.712841836Z 37 PC: 13021 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:52.714155655Z 37 PC: 13021 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:52.716441737Z 37 PC: 13021 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:52.717766103Z 37 PC: 13021 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:52.719109229Z 37 PC: 13021 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:52.721566863Z 37 PC: 13021 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:52.723602119Z 37 PC: 13021 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:52.725635545Z 37 PC: 13021 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:52.728172387Z 37 PC: 13021 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:52.730157328Z 37 PC: 13021 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:52.731831307Z 37 PC: 13021 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:52.733566858Z 76 PC: 13060 | Terminate with return code (Return code = '0')