Sample viewer

vx.netlux.org/Virus.DOS.HLLP.PPZ.8516

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:04.22028128Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:04.221936996Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:04.223101078Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:04.224230868Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:58:04.226531506Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:04.227846846Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:04.229224809Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:04.23107798Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:04.232528923Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:04.233993836Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:04.235873267Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:04.237413591Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:04.23876035Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:04.240798035Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:04.241988235Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:04.243133835Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:04.24500853Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:04.24614675Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:04.247260222Z 53 PC: 14e9a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:04.248808218Z 37 PC: 14eaf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:04.250872303Z 37 PC: 14eb7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:04.252702175Z 37 PC: 14ebf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:04.255103137Z 37 PC: 14ec7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:04.256707413Z 68 PC: 159fc | I/O control for devices (Set for = '')
2018-12-17T21:58:04.295981677Z 37 PC: 145b1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:04.297341875Z 48 PC: 15722 | Get DOS version
2018-12-17T21:58:04.298592875Z 53 PC: 14cd1 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:58:04.299442757Z 37 PC: 14ced | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T21:58:04.300469902Z 53 PC: 14cd1 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T21:58:04.30247406Z 37 PC: 14ced | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T21:58:04.303577581Z 53 PC: 14cd1 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:04.304489109Z 37 PC: 14ced | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:04.305938685Z 51 PC: 14bbf | Get or set Ctrl-Break
2018-12-17T21:58:04.306871161Z 60 PC: 15560 | Create or truncate file
2018-12-17T21:58:04.502562929Z 65 PC: 156a9 | Delete file (Filename = '/�')
2018-12-17T21:58:04.51379218Z 48 PC: 15722 | Get DOS version
2018-12-17T21:58:04.515614583Z 61 PC: 15560 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:58:04.534812038Z 66 PC: 15692 | Move file pointer
2018-12-17T21:58:04.537300205Z 63 PC: 15633 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T21:58:04.544495404Z 62 PC: 155b0 | Close file
2018-12-17T21:58:04.550749075Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:04.552640959Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:04.553807867Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:04.554940491Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:58:04.556464399Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:04.557553788Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:04.558579336Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:04.56008979Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:04.561568286Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:04.56302928Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:04.565180824Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:04.566296749Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:04.567383861Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:04.56911619Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:04.570139882Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:04.57109398Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:04.572621507Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:04.573599576Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:04.574548781Z 37 PC: 14ff1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:04.575957413Z 76 PC: 15030 | Terminate with return code (Return code = '8')