Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Mrweb.8064

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:53.205132569Z 53 PC: 138da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:53.206694045Z 53 PC: 138da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:53.207810512Z 53 PC: 138da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:53.208881331Z 53 PC: 138da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:53.210351479Z 53 PC: 138da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:53.211437459Z 53 PC: 138da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:53.212453407Z 53 PC: 138da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:53.213664788Z 53 PC: 138da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:53.226140362Z 53 PC: 138da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:53.227126508Z 53 PC: 138da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:53.228350654Z 53 PC: 138da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:53.22948834Z 53 PC: 138da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:53.230434719Z 53 PC: 138da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:53.231405429Z 53 PC: 138da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:53.232502111Z 53 PC: 138da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:53.233444121Z 53 PC: 138da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:53.234377389Z 53 PC: 138da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:53.235872778Z 53 PC: 138da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:53.236829256Z 53 PC: 138da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:53.237810344Z 37 PC: 138ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:53.239072291Z 37 PC: 138f7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:53.239945592Z 37 PC: 138ff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:53.24087443Z 37 PC: 13907 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:53.242633123Z 68 PC: 14551 | I/O control for devices (Set for = '')
2018-12-17T22:45:53.243923954Z 53 PC: 136af | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:53.244958522Z 37 PC: 136cb | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:53.246564314Z 53 PC: 136af | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:45:53.247545433Z 37 PC: 136cb | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:45:53.248498773Z 53 PC: 136af | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:53.250106403Z 37 PC: 136cb | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:53.251084299Z 51 PC: 1359d | Get or set Ctrl-Break
2018-12-17T22:45:53.251783783Z 48 PC: 14162 | Get DOS version
2018-12-17T22:45:53.253609321Z 26 PC: 1364e | Set disk transfer address
2018-12-17T22:45:53.265145592Z 78 PC: 1365a | Find first file
2018-12-17T22:45:53.27117951Z 60 PC: 13fa0 | Create or truncate file
2018-12-17T22:45:53.289035162Z 65 PC: 140e9 | Delete file (Filename = 'A:\�')
2018-12-17T22:45:53.300356869Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.31010775Z 61 PC: 13fa0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:45:53.31697557Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.318301393Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.319554773Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.321469473Z 63 PC: 14073 | Read file or device (Read 8064 bytes on handle 6)
2018-12-17T22:45:53.328811509Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.330868868Z 26 PC: 1364e | Set disk transfer address
2018-12-17T22:45:53.33235245Z 78 PC: 1365a | Find first file
2018-12-17T22:45:53.339671418Z 61 PC: 13fa0 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:45:53.346411275Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.34930349Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.350982232Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.35274271Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:45:53.355600055Z 63 PC: 14073 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:45:53.363229793Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:45:53.365167292Z 63 PC: 14073 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:45:53.372286572Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:45:53.373861149Z 63 PC: 14073 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:45:53.376515958Z 66 PC: 140d2 | Move file pointer
2018-12-17T22:45:53.378388935Z 63 PC: 14073 | Read file or device (Read 8064 bytes on handle 6)
2018-12-17T22:45:53.385856438Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.387591746Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.397853947Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.404908292Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.406285941Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.410536249Z 26 PC: 1364e | Set disk transfer address
2018-12-17T22:45:53.412053834Z 78 PC: 1365a | Find first file
2018-12-17T22:45:53.419732144Z 61 PC: 13fa0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:45:53.428162251Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.429682339Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.431248473Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.43339025Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.434896757Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.444985961Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.452832015Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.453926479Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.45779163Z 61 PC: 13fa0 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:45:53.464848289Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.466086079Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.467311888Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.468821285Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.470573946Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.48030447Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.487899598Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.488910725Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.492335389Z 61 PC: 13fa0 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:45:53.499773114Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.50104962Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.502289675Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.504000206Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.505374048Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.515224067Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.522158023Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.523105396Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.525343114Z 61 PC: 13fa0 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:45:53.529987783Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.530984084Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.531936882Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.533178947Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.534277563Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.541075382Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.548854777Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.549900564Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.553343995Z 61 PC: 13fa0 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:45:53.566072134Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.56736077Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.568602861Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.570131767Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.571933702Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.582007201Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.58932734Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.594045066Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.597579629Z 61 PC: 13fa0 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:45:53.605155437Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.60711317Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.608895132Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.611117329Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.62223899Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.632092446Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.642273382Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.643301162Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.646773884Z 61 PC: 13fa0 | Open file (Filename = 'PAH.COM')
2018-12-17T22:45:53.65352202Z 66 PC: 14650 | Move file pointer
2018-12-17T22:45:53.655013362Z 66 PC: 1465e | Move file pointer
2018-12-17T22:45:53.656365858Z 66 PC: 1466c | Move file pointer
2018-12-17T22:45:53.658369914Z 87 PC: 1361e | Get or set file date and time
2018-12-17T22:45:53.659902261Z 67 PC: 135d7 | Get or set file attributes
2018-12-17T22:45:53.669595791Z 62 PC: 13ff0 | Close file
2018-12-17T22:45:53.677261239Z 26 PC: 13672 | Set disk transfer address
2018-12-17T22:45:53.678246442Z 79 PC: 13677 | Find next file
2018-12-17T22:45:53.685294783Z 26 PC: 1364e | Set disk transfer address
2018-12-17T22:45:53.686689812Z 78 PC: 1365a | Find first file
2018-12-17T22:45:53.696878441Z 37 PC: 136cb | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:53.697968872Z 37 PC: 136cb | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:45:53.700067187Z 37 PC: 136cb | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:53.702675739Z 64 PC: 13cf8 | Write file or device (Write 15 bytes on handle 1)
2018-12-17T22:45:53.708072933Z 77 PC: 1383a | Get program return code
2018-12-17T22:45:53.710784817Z 64 PC: 13cf8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:45:53.712450455Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:53.713560739Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:53.714859206Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:53.716460242Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:53.717502637Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:53.718686476Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:53.720691379Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:53.721854464Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:53.723167087Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:53.725195233Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:53.726650733Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:53.72814647Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:53.730035376Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:53.731472534Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:53.732959637Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:53.734844049Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:53.736268206Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:53.73767266Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:53.739485662Z 37 PC: 13a31 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:53.74080376Z 76 PC: 13a70 | Terminate with return code (Return code = '0')