Sample viewer

vx.netlux.org/Virus.DOS.HLLP.DNVG.5040

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:39.923589969Z 53 PC: 132ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:39.924979139Z 53 PC: 132ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:39.927003041Z 53 PC: 132ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:39.928664863Z 53 PC: 132ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:39.930360459Z 53 PC: 132ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:39.932477056Z 53 PC: 132ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:39.934103291Z 53 PC: 132ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:39.935650047Z 53 PC: 132ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:39.93919628Z 53 PC: 132ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:39.940725122Z 53 PC: 132ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:39.942248775Z 53 PC: 132ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:39.944699108Z 53 PC: 132ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:39.945976588Z 53 PC: 132ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:39.947263566Z 53 PC: 132ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:39.948812617Z 53 PC: 132ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:39.952423461Z 53 PC: 132ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:39.955472048Z 53 PC: 132ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:39.958263172Z 53 PC: 132ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:39.961854259Z 53 PC: 132ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:39.963596823Z 37 PC: 132cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:39.965416401Z 37 PC: 132d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:39.967967725Z 37 PC: 132df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:39.970569343Z 37 PC: 132e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:39.973010018Z 68 PC: 13b4a | I/O control for devices (Set for = '')
2018-12-17T22:49:39.978375659Z 48 PC: 13870 | Get DOS version
2018-12-17T22:49:39.980689887Z 48 PC: 13870 | Get DOS version
2018-12-17T22:49:39.983004786Z 61 PC: 13722 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:49:39.992452366Z 63 PC: 137f5 | Read file or device (Read 5040 bytes on handle 5)
2018-12-17T22:49:40.000401491Z 62 PC: 13772 | Close file
2018-12-17T22:49:40.00283373Z 26 PC: 130bd | Set disk transfer address
2018-12-17T22:49:40.00482936Z 78 PC: 130c9 | Find first file
2018-12-17T22:49:40.012859547Z 26 PC: 130e1 | Set disk transfer address
2018-12-17T22:49:40.014490952Z 79 PC: 130e6 | Find next file
2018-12-17T22:49:40.017643374Z 48 PC: 13870 | Get DOS version
2018-12-17T22:49:40.020299935Z 26 PC: 130bd | Set disk transfer address
2018-12-17T22:49:40.022022081Z 78 PC: 130c9 | Find first file
2018-12-17T22:49:40.029384774Z 48 PC: 13870 | Get DOS version
2018-12-17T22:49:40.033702957Z 67 PC: 13046 | Get or set file attributes
2018-12-17T22:49:40.05176987Z 61 PC: 13722 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:49:40.060217882Z 66 PC: 13854 | Move file pointer
2018-12-17T22:49:40.063463841Z 63 PC: 137f5 | Read file or device (Read 5040 bytes on handle 5)
2018-12-17T22:49:40.065567172Z 66 PC: 13854 | Move file pointer
2018-12-17T22:49:40.067535Z 64 PC: 13753 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:49:40.07104275Z 66 PC: 13854 | Move file pointer
2018-12-17T22:49:40.073931277Z 64 PC: 137f5 | Write file or device (Write 5040 bytes on handle 5)
2018-12-17T22:49:40.083038748Z 87 PC: 1308d | Get or set file date and time
2018-12-17T22:49:40.086013687Z 67 PC: 13046 | Get or set file attributes
2018-12-17T22:49:40.097952567Z 62 PC: 13772 | Close file
2018-12-17T22:49:40.105798999Z 53 PC: 1322c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:40.108491408Z 37 PC: 13235 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:40.110225355Z 53 PC: 1322c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:40.111939386Z 37 PC: 13235 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:40.114423433Z 53 PC: 1322c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:40.116638835Z 37 PC: 13235 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:40.118229503Z 53 PC: 1322c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:40.11986734Z 37 PC: 13235 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:40.122200865Z 53 PC: 1322c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:40.123798767Z 37 PC: 13235 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:40.125846254Z 53 PC: 1322c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:40.127938885Z 37 PC: 13235 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:40.129532299Z 53 PC: 1322c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:40.131158324Z 37 PC: 13235 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:40.133240265Z 53 PC: 1322c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:40.135080242Z 37 PC: 13235 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:40.136600599Z 53 PC: 1322c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:40.138818485Z 37 PC: 13235 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:40.140866022Z 53 PC: 1322c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:40.142498099Z 37 PC: 13235 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:40.145226344Z 53 PC: 1322c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:40.147013582Z 37 PC: 13235 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:40.1487051Z 53 PC: 1322c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:40.150792302Z 37 PC: 13235 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:40.160043813Z 53 PC: 1322c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:40.162081582Z 37 PC: 13235 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:40.163993704Z 53 PC: 1322c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:40.167114037Z 37 PC: 13235 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:40.16898387Z 53 PC: 1322c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:40.170841259Z 37 PC: 13235 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:40.173515814Z 53 PC: 1322c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:40.17507848Z 37 PC: 13235 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:40.176498027Z 53 PC: 1322c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:40.178188633Z 37 PC: 13235 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:40.179845336Z 53 PC: 1322c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:40.181697926Z 37 PC: 13235 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:40.18331778Z 53 PC: 1322c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:40.185057899Z 37 PC: 13235 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:40.187003685Z 41 PC: 131e3 | Parse filename
2018-12-17T22:49:40.188782186Z 41 PC: 131f1 | Parse filename
2018-12-17T22:49:40.190890728Z 75 PC: 131fc | Execute program
2018-12-17T22:49:40.211566673Z 80 PC: 18859 | Set current PSP
2018-12-17T22:49:40.212362538Z 48 PC: 1885e | Get DOS version
2018-12-17T22:49:40.214158282Z 99 PC: 1f040 | Get DBCS lead byte table pointer
2018-12-17T22:49:40.216277504Z 101 PC: 188e4 | Get extended country info
2018-12-17T22:49:40.217439146Z 99 PC: 188ea | Get DBCS lead byte table pointer
2018-12-17T22:49:40.219289483Z 74 PC: 1894c | Reallocate memory
2018-12-17T22:49:40.220566231Z 25 PC: 18983 | Get default drive
2018-12-17T22:49:40.221714068Z 37 PC: 18443 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:49:40.223384206Z 37 PC: 1844a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:40.224507316Z 37 PC: 18451 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:40.227726784Z 74 PC: 175ec | Reallocate memory
2018-12-17T22:49:40.229610964Z 72 PC: 1762d | Allocate memory
2018-12-17T22:49:40.231084833Z 72 PC: 17665 | Allocate memory
2018-12-17T22:49:40.232946992Z 72 PC: 1766d | Allocate memory