Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Zyx.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:57.885637264Z 53 PC: 13cda | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:57.887236975Z 53 PC: 13cda | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:57.891396416Z 53 PC: 13cda | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:57.900637175Z 53 PC: 13cda | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:57.901989502Z 53 PC: 13cda | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:57.904622961Z 53 PC: 13cda | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:57.906114392Z 53 PC: 13cda | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:57.907573862Z 53 PC: 13cda | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:57.912208747Z 53 PC: 13cda | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:57.913863031Z 53 PC: 13cda | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:57.915345849Z 53 PC: 13cda | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:57.917371802Z 53 PC: 13cda | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:57.919647985Z 53 PC: 13cda | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:57.921142773Z 53 PC: 13cda | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:57.923225587Z 53 PC: 13cda | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:57.924951031Z 53 PC: 13cda | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:57.926561912Z 53 PC: 13cda | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:57.928830743Z 53 PC: 13cda | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:57.930206697Z 53 PC: 13cda | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:57.931917242Z 37 PC: 13cef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:57.93334491Z 37 PC: 13cf7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:57.935459983Z 37 PC: 13cff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:57.936539097Z 37 PC: 13d07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:57.938732676Z 68 PC: 14a72 | I/O control for devices (Set for = '')
2018-12-17T22:45:57.940679Z 64 PC: 140f8 | Write file or device (Write 46 bytes on handle 1)
2018-12-17T22:45:57.945460317Z 64 PC: 140f8 | Write file or device (Write 47 bytes on handle 1)
2018-12-17T22:45:57.952489306Z 60 PC: 14a56 | Create or truncate file
2018-12-17T22:45:57.972223891Z 68 PC: 14a72 | I/O control for devices (Set for = '�$��*�� ��{��@��%��?�����B�����Y��>�����硢Z�������b��d�����j��f��h��^�����������"����`��[��_��1��\����������w��x��')
2018-12-17T22:45:57.974082962Z 64 PC: 140d3 | Write file or device (Write 26 bytes on handle 5)
2018-12-17T22:45:57.978439004Z 62 PC: 14112 | Close file
2018-12-17T22:45:57.988526041Z 41 PC: 13c3b | Parse filename
2018-12-17T22:45:57.990423621Z 41 PC: 13c49 | Parse filename
2018-12-17T22:45:57.992590921Z 75 PC: 13c54 | Execute program
2018-12-17T22:45:58.012722907Z 80 PC: 1cdf9 | Set current PSP
2018-12-17T22:45:58.013435791Z 48 PC: 1cdfe | Get DOS version
2018-12-17T22:45:58.015286819Z 99 PC: 235e0 | Get DBCS lead byte table pointer
2018-12-17T22:45:58.017674493Z 101 PC: 1ce84 | Get extended country info
2018-12-17T22:45:58.018792987Z 99 PC: 1ce8a | Get DBCS lead byte table pointer
2018-12-17T22:45:58.020243464Z 74 PC: 1ceec | Reallocate memory
2018-12-17T22:45:58.021533961Z 25 PC: 1cf23 | Get default drive
2018-12-17T22:45:58.022489908Z 37 PC: 1c9e3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:45:58.023980648Z 37 PC: 1c9ea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:58.024944088Z 37 PC: 1c9f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:58.028846257Z 74 PC: 1bb8c | Reallocate memory
2018-12-17T22:45:58.030349808Z 72 PC: 1bbcd | Allocate memory
2018-12-17T22:45:58.03188691Z 72 PC: 1bc05 | Allocate memory
2018-12-17T22:45:58.033420697Z 72 PC: 1bc0d | Allocate memory