Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Lerm.41732

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:08.53548927Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:48:08.537280481Z 53 PC: 12be0 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:08.53980172Z 53 PC: 12bed | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:48:08.541039965Z 53 PC: 12bfa | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:48:08.54452664Z 53 PC: 12c07 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:48:08.546432069Z 37 PC: 12c1b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:08.547740907Z 74 PC: 12af7 | Reallocate memory
2018-12-17T22:48:08.550722143Z 68 PC: 162cd | I/O control for devices (Set for = '��H ')
2018-12-17T22:48:08.552615426Z 68 PC: 162cd | I/O control for devices (Set for = '')
2018-12-17T22:48:08.554233065Z 53 PC: 1506e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:08.557800179Z 53 PC: 1506e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:08.559986057Z 53 PC: 1506e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:08.561066451Z 53 PC: 1506e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:08.562823606Z 53 PC: 1506e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:08.563901336Z 53 PC: 1506e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:08.564797474Z 53 PC: 1506e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:08.566272863Z 53 PC: 1506e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:08.567322512Z 53 PC: 1506e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:08.568391445Z 53 PC: 1506e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:08.570140349Z 53 PC: 1506e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:08.571162906Z 53 PC: 1507e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:08.572057659Z 53 PC: 1508b | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:08.573994266Z 37 PC: 15187 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:08.575025472Z 37 PC: 15187 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:08.576040785Z 37 PC: 15187 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:08.590526486Z 37 PC: 15187 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:08.591592553Z 37 PC: 15187 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:08.592863874Z 37 PC: 15187 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:08.597542716Z 37 PC: 15187 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:08.598876115Z 37 PC: 15187 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:08.600242011Z 37 PC: 15187 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:08.60219039Z 37 PC: 15187 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:08.604074696Z 37 PC: 15192 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:08.605919288Z 37 PC: 1519c | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:08.611204672Z 68 PC: 162cd | I/O control for devices (Set for = '')
2018-12-17T22:48:08.616542973Z 61 PC: 16234 | Open file (Filename = 'c:\msdos.sys')
2018-12-17T22:48:08.623069151Z 63 PC: 1625a | Read file or device (Read 100 bytes on handle 5)
2018-12-17T22:48:08.630013583Z 47 PC: 17995 | Get disk transfer address
2018-12-17T22:48:08.631139144Z 26 PC: 1799e | Set disk transfer address
2018-12-17T22:48:08.632181164Z 78 PC: 179a8 | Find first file
2018-12-17T22:48:08.638798907Z 26 PC: 179b1 | Set disk transfer address
2018-12-17T22:48:08.640801372Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.657155167Z 61 PC: 17dd6 | Open file (Filename = '������')
2018-12-17T22:48:08.664264415Z 68 PC: 17f5f | I/O control for devices (Set for = '� ��')
2018-12-17T22:48:08.666043761Z 68 PC: 162cd | I/O control for devices (Set for = ';p t�w��u��?��u����2')
2018-12-17T22:48:08.668014296Z 66 PC: 162f5 | Move file pointer
2018-12-17T22:48:08.670603997Z 63 PC: 16326 | Read file or device (Read 41472 bytes on handle 6)
2018-12-17T22:48:08.678797213Z 63 PC: 16326 | Read file or device (Read 512 bytes on handle 6)
2018-12-17T22:48:08.682224639Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.684870412Z 47 PC: 17995 | Get disk transfer address
2018-12-17T22:48:08.686592378Z 26 PC: 1799e | Set disk transfer address
2018-12-17T22:48:08.687737141Z 78 PC: 179a8 | Find first file
2018-12-17T22:48:08.693644843Z 26 PC: 179b1 | Set disk transfer address
2018-12-17T22:48:08.695625232Z 47 PC: 179cc | Get disk transfer address
2018-12-17T22:48:08.69687145Z 26 PC: 179d5 | Set disk transfer address
2018-12-17T22:48:08.698075957Z 79 PC: 179d9 | Find next file
2018-12-17T22:48:08.700855111Z 26 PC: 179e2 | Set disk transfer address
2018-12-17T22:48:08.702302303Z 47 PC: 17995 | Get disk transfer address
2018-12-17T22:48:08.703271135Z 26 PC: 1799e | Set disk transfer address
2018-12-17T22:48:08.704929464Z 78 PC: 179a8 | Find first file
2018-12-17T22:48:08.710865334Z 26 PC: 179b1 | Set disk transfer address
2018-12-17T22:48:08.712571941Z 47 PC: 17995 | Get disk transfer address
2018-12-17T22:48:08.714111759Z 26 PC: 1799e | Set disk transfer address
2018-12-17T22:48:08.717471328Z 78 PC: 179a8 | Find first file
2018-12-17T22:48:08.723713968Z 26 PC: 179b1 | Set disk transfer address
2018-12-17T22:48:08.725985478Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.731613179Z 60 PC: 17c17 | Create or truncate file
2018-12-17T22:48:08.748923256Z 68 PC: 162cd | I/O control for devices (Set for = '�p����F ��H>��i�i�HpGmSv����L��5���/�HŽ���錡P=��XC��c�o���)s�� +��k����Y�-Hs ��S�(ЖF�U�A���\t')
2018-12-17T22:48:08.752739233Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.761701654Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.768675884Z 64 PC: 17f19 | Write file or device (Write 13 bytes on handle 6)
2018-12-17T22:48:08.773213108Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.781208342Z 86 PC: 17ee7 | Rename file
2018-12-17T22:48:08.793390297Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.799867665Z 60 PC: 17c17 | Create or truncate file
2018-12-17T22:48:08.810682412Z 68 PC: 162cd | I/O control for devices (Set for = '�p����F ��H>��i�i�HpGmSv����L��5���/�HŽ���錡P=��XC��c�o���)s�� +��k����Y�-Hs ��S�(ЖF�U�A���\t')
2018-12-17T22:48:08.812978878Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.816340803Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.822960605Z 60 PC: 17c17 | Create or truncate file
2018-12-17T22:48:08.834213473Z 68 PC: 162cd | I/O control for devices (Set for = '�p����F ��H>��i�i�HpGmSv����L��5���/�HŽ���錡P=��XC��c�o���)s�� +��k����Y�-Hs ��S�(ЖF�U�A���\t')
2018-12-17T22:48:08.838493197Z 64 PC: 17f19 | Write file or device (Write 41732 bytes on handle 6)
2018-12-17T22:48:08.849045187Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.857870066Z 67 PC: 178cf | Get or set file attributes
2018-12-17T22:48:08.864693737Z 61 PC: 17dd6 | Open file (Filename = 'A:\TEST.swp')
2018-12-17T22:48:08.874641075Z 37 PC: 15211 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:08.875717624Z 37 PC: 15211 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:08.877785118Z 37 PC: 15211 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:08.878833859Z 37 PC: 15211 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:08.879852701Z 37 PC: 15211 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:08.88236713Z 37 PC: 15211 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:08.883622507Z 37 PC: 15211 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:08.884645552Z 37 PC: 15211 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:08.886620564Z 37 PC: 15211 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:08.887671549Z 37 PC: 15211 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:08.888673865Z 37 PC: 15211 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:08.890641477Z 37 PC: 1521f | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:08.89165249Z 37 PC: 15228 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:08.892986841Z 37 PC: 12c27 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:08.894978939Z 37 PC: 12c32 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:48:08.896014521Z 37 PC: 12c3d | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:48:08.897039287Z 37 PC: 12c48 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:48:08.899859441Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.902104338Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.904294756Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.907331176Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.909266641Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.911037577Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.913046483Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.914497556Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.91600824Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.918547992Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.920453139Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.921929472Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.925838255Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.927238455Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.928594138Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.930606803Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.933448397Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.935405107Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.937470066Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.938866268Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.940051573Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.94157849Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.942774621Z 62 PC: 178e8 | Close file
2018-12-17T22:48:08.943968483Z 76 PC: 12bcb | Terminate with return code (Return code = '255')