Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Unsteady.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:25.204968123Z 53 PC: 139ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:25.207028792Z 53 PC: 139ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:25.20864839Z 53 PC: 139ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:25.209946927Z 53 PC: 139ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:25.211626421Z 53 PC: 139ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:25.21267419Z 53 PC: 139ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:25.213609081Z 53 PC: 139ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:25.215403898Z 53 PC: 139ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:25.216399496Z 53 PC: 139ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:25.217279056Z 53 PC: 139ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:25.218409143Z 53 PC: 139ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:25.220271991Z 53 PC: 139ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:25.221523164Z 53 PC: 139ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:25.222802716Z 53 PC: 139ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:25.224768235Z 53 PC: 139ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:25.22610632Z 53 PC: 139ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:25.227343087Z 53 PC: 139ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:25.229374721Z 53 PC: 139ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:25.230725012Z 53 PC: 139ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:25.23219507Z 37 PC: 139cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:25.23954932Z 37 PC: 139d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:25.240611601Z 37 PC: 139df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:25.241639924Z 37 PC: 139e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:25.243991462Z 68 PC: 1468e | I/O control for devices (Set for = '')
2018-12-17T22:49:25.24633723Z 44 PC: 147c5 | Get time 0x147c5: mov word ptr [0x3e], cx
0x147c9: mov word ptr [0x40], dx
0x147cd: retf
0x147ce: mov di, 0x52
0x147d1: push ds
0x147d2: pop es
0x147d3: mov cx, 0x1d7c
0x147d6: sub cx, di
0x147d8: shr cx, 1
0x147da: xor ax, ax
0x147dc: cld
0x147dd: rep stosd dword ptr es:[di], eax
0x147df: ret
0x147e0: add byte ptr [bx + si], al
0x147e2: add byte ptr [bx + si], al
0x147e4: add byte ptr [bx + si], al
0x147e6: add byte ptr [bx + si], al
0x147e8: add byte ptr [bx + si], al
0x147ea: daa
0x147eb: pop ss
2018-12-17T22:49:25.250059317Z 42 PC: 13577 | Get date 0x13577: xor ah, ah
0x13579: les di, ptr [bp + 6]
0x1357c: stosw word ptr es:[di], ax
0x1357d: mov al, dl
0x1357f: les di, ptr [bp + 0xa]
0x13582: stosw word ptr es:[di], ax
0x13583: mov al, dh
0x13585: les di, ptr [bp + 0xe]
0x13588: stosw word ptr es:[di], ax
0x13589: xchg ax, cx
0x1358a: les di, ptr [bp + 0x12]
0x1358d: stosw word ptr es:[di], ax
0x1358e: pop bp
0x1358f: retf 0x10
0x13592: push bp
0x13593: mov bp, sp
0x13595: mov cx, word ptr [bp + 0xa]
0x13598: mov dh, byte ptr [bp + 8]
0x1359b: mov dl, byte ptr [bp + 6]
0x1359e: mov ah, 0x2b
2018-12-17T22:49:25.253385531Z 48 PC: 142d3 | Get DOS version
2018-12-17T22:49:25.256196912Z 67 PC: 1364c | Get or set file attributes
2018-12-17T22:49:25.274272019Z 25 PC: 14360 | Get default drive
2018-12-17T22:49:25.275642863Z 71 PC: 14373 | Get current directory
2018-12-17T22:49:25.279430504Z 54 PC: 135ec | Get free disk space
2018-12-17T22:49:25.288772981Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.289836078Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.2978335Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.299339888Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.302798226Z 26 PC: 136e7 | Set disk transfer address
2018-12-17T22:49:25.304698432Z 79 PC: 136ec | Find next file
2018-12-17T22:49:25.307758494Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.309221323Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.316346257Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.317867681Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.322268329Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.32457103Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.327801454Z 67 PC: 1364c | Get or set file attributes
2018-12-17T22:49:25.337866087Z 86 PC: 1429e | Rename file
2018-12-17T22:49:25.364712493Z 61 PC: 14111 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:49:25.371755935Z 60 PC: 14111 | Create or truncate file
2018-12-17T22:49:25.383090537Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.38550763Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.389341661Z 61 PC: 14111 | Open file (Filename = 'A:\HKSYRT.TMP')
2018-12-17T22:49:25.396796164Z 63 PC: 141e4 | Read file or device (Read 5667 bytes on handle 5)
2018-12-17T22:49:25.405808478Z 64 PC: 141e4 | Write file or device (Write 5667 bytes on handle 6)
2018-12-17T22:49:25.414570595Z 63 PC: 141e4 | Read file or device (Read 5667 bytes on handle 7)
2018-12-17T22:49:25.421280339Z 64 PC: 141e4 | Write file or device (Write 407 bytes on handle 6)
2018-12-17T22:49:25.424606153Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:49:25.426928207Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.434916961Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.436953612Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.439604789Z 65 PC: 1425a | Delete file (Filename = 'HKSYRT.tmp')
2018-12-17T22:49:25.451836117Z 61 PC: 14111 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:49:25.458570834Z 63 PC: 141e4 | Read file or device (Read 5667 bytes on handle 5)
2018-12-17T22:49:25.467616958Z 60 PC: 14111 | Create or truncate file
2018-12-17T22:49:25.478798122Z 63 PC: 141e4 | Read file or device (Read 5667 bytes on handle 5)
2018-12-17T22:49:25.486755332Z 64 PC: 141e4 | Write file or device (Write 3866 bytes on handle 6)
2018-12-17T22:49:25.496396618Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.498524908Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.507749027Z 41 PC: 13924 | Parse filename
2018-12-17T22:49:25.510684987Z 41 PC: 13932 | Parse filename
2018-12-17T22:49:25.512403474Z 75 PC: 1393d | Execute program
2018-12-17T22:49:25.528627012Z 9 PC: 192ee | Display string (String= 'Fast Draft 480 board not installed ')
2018-12-17T22:49:25.536308446Z 65 PC: 1425a | Delete file (Filename = 'A:\aHKSYRT.tmp')
2018-12-17T22:49:25.548043508Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.549508973Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.555703125Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.557684291Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.562285873Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.564760187Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.574494124Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.575749899Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.580570605Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.581791566Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.585980635Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.588090804Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.59224073Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.593296683Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.599017114Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.600425815Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.612717796Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.614321674Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.625655087Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.62673697Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.633181819Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.6349025Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.64091579Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.642254804Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.646004227Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.647041807Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.650167188Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.651615454Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.655768614Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.6570746Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.661548764Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.662393315Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.665025372Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.666321712Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.668956519Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.670185053Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.675493466Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.676796217Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.681146737Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.683232264Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.687916636Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.689198023Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.694283535Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.696293708Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.700666299Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.702672043Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.70733413Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.708627988Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.713655342Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.715733493Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.720117785Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.721613235Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.726733474Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.728023651Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.732399863Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.735246297Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.739677639Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.740970488Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.746305999Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.747616141Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.752089985Z 14 PC: 143b9 | Set default drive (Drive = 'A')
2018-12-17T22:49:25.754493664Z 25 PC: 143bd | Get default drive
2018-12-17T22:49:25.75581397Z 59 PC: 14427 | Change current directory
2018-12-17T22:49:25.760521436Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.76261127Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.772150208Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.773366412Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.7777703Z 26 PC: 136e7 | Set disk transfer address
2018-12-17T22:49:25.779313423Z 79 PC: 136ec | Find next file
2018-12-17T22:49:25.786443632Z 26 PC: 136c3 | Set disk transfer address
2018-12-17T22:49:25.788398611Z 78 PC: 136cf | Find first file
2018-12-17T22:49:25.795067286Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.796328129Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.800292464Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.80187727Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.805091174Z 67 PC: 1364c | Get or set file attributes
2018-12-17T22:49:25.815540065Z 86 PC: 1429e | Rename file
2018-12-17T22:49:25.830193436Z 61 PC: 14111 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:49:25.841741782Z 60 PC: 14111 | Create or truncate file
2018-12-17T22:49:25.855687599Z 25 PC: 137c5 | Get default drive
2018-12-17T22:49:25.858245031Z 71 PC: 137e4 | Get current directory
2018-12-17T22:49:25.861622886Z 61 PC: 14111 | Open file (Filename = 'A:\HKSYRT.TMP')
2018-12-17T22:49:25.868557382Z 63 PC: 141e4 | Read file or device (Read 5667 bytes on handle 5)
2018-12-17T22:49:25.877728553Z 64 PC: 141e4 | Write file or device (Write 5667 bytes on handle 6)
2018-12-17T22:49:25.886374158Z 63 PC: 141e4 | Read file or device (Read 5667 bytes on handle 7)
2018-12-17T22:49:25.893188773Z 64 PC: 141e4 | Write file or device (Write 27 bytes on handle 6)
2018-12-17T22:49:25.897331221Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:49:25.899210236Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.90719144Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.910427565Z 62 PC: 14161 | Close file
2018-12-17T22:49:25.91294891Z 65 PC: 1425a | Delete file (Filename = 'HKSYRT.tmp')
2018-12-17T22:49:25.924709991Z 14 PC: 143b9 | Set default drive (Drive = 'A')
2018-12-17T22:49:25.926973998Z 25 PC: 143bd | Get default drive
2018-12-17T22:49:25.92862976Z 59 PC: 14427 | Change current directory
2018-12-17T22:49:25.933113849Z 64 PC: 13dd8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:49:25.935812332Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:25.937485475Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:25.938835788Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:25.940890896Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:25.942555709Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:25.943904221Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:25.945450106Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:25.947592158Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:25.948981806Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:25.95033807Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:25.952641761Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:25.953988251Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:25.955325445Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:25.957623817Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:25.958959878Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:25.960308848Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:25.962609169Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:25.963961267Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:25.965309394Z 37 PC: 13b11 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:25.967645398Z 76 PC: 13b50 | Terminate with return code (Return code = '0')