Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Nazi.8000.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:07.215987123Z 53 PC: 13eea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:07.217445926Z 53 PC: 13eea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:07.218476201Z 53 PC: 13eea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:07.219432547Z 53 PC: 13eea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:07.221024079Z 53 PC: 13eea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:07.222095574Z 53 PC: 13eea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:07.223319988Z 53 PC: 13eea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:07.224817191Z 53 PC: 13eea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:07.225882428Z 53 PC: 13eea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:07.226581017Z 53 PC: 13eea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:07.227360853Z 53 PC: 13eea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:07.228332056Z 53 PC: 13eea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:07.229080876Z 53 PC: 13eea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:07.229833555Z 53 PC: 13eea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:07.239185647Z 53 PC: 13eea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:07.240161136Z 53 PC: 13eea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:07.241139649Z 53 PC: 13eea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:07.24272467Z 53 PC: 13eea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:07.243675912Z 53 PC: 13eea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:07.244493573Z 37 PC: 13eff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:07.245876549Z 37 PC: 13f07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:07.246806173Z 37 PC: 13f0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:07.247752035Z 37 PC: 13f17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:07.249581049Z 68 PC: 14a47 | I/O control for devices (Set for = '')
2018-12-17T22:46:07.39253188Z 37 PC: 13681 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:07.393901763Z 48 PC: 14772 | Get DOS version
2018-12-17T22:46:07.396009333Z 53 PC: 13d2f | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:07.397148192Z 37 PC: 13d4b | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:07.398261271Z 53 PC: 13d2f | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:46:07.400002128Z 37 PC: 13d4b | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:46:07.40109839Z 53 PC: 13d2f | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:07.402342838Z 37 PC: 13d4b | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:07.40445233Z 51 PC: 13c1d | Get or set Ctrl-Break
2018-12-17T22:46:07.405529776Z 60 PC: 145b0 | Create or truncate file
2018-12-17T22:46:07.42234036Z 65 PC: 146f9 | Delete file (Filename = '\�')
2018-12-17T22:46:07.433829321Z 48 PC: 14772 | Get DOS version
2018-12-17T22:46:07.43539538Z 61 PC: 145b0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:46:07.441969946Z 66 PC: 146e2 | Move file pointer
2018-12-17T22:46:07.444769604Z 63 PC: 14683 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:46:07.451301882Z 62 PC: 14600 | Close file
2018-12-17T22:46:07.457412228Z 37 PC: 14041 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:07.458886248Z 37 PC: 14041 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:07.460368353Z 37 PC: 14041 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:07.461596671Z 37 PC: 14041 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:07.463779672Z 37 PC: 14041 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:07.465077619Z 37 PC: 14041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:07.466245182Z 37 PC: 14041 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:07.467610577Z 37 PC: 14041 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:07.469578859Z 37 PC: 14041 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:07.470599757Z 37 PC: 14041 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:07.47166651Z 37 PC: 14041 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:07.474049919Z 37 PC: 14041 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:07.475056166Z 37 PC: 14041 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:07.476260217Z 37 PC: 14041 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:07.477775293Z 37 PC: 14041 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:07.478878653Z 37 PC: 14041 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:07.480647746Z 37 PC: 14041 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:07.482749947Z 37 PC: 14041 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:07.483904134Z 37 PC: 14041 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:07.48503507Z 76 PC: 14080 | Terminate with return code (Return code = '8')