Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Fataler

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:24.043070213Z 48 PC: 13161 | Get DOS version
2018-12-17T22:50:24.045770184Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:50:24.047438346Z 74 PC: 12d49 | Reallocate memory
2018-12-17T22:50:24.048923519Z 74 PC: 12d4d | Reallocate memory
2018-12-17T22:50:24.053171061Z 37 PC: 15ce3 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:50:24.059825719Z 74 PC: 18e85 | Reallocate memory
2018-12-17T22:50:24.062793443Z 75 PC: 18e1d | Execute program
2018-12-17T22:50:24.090164215Z 80 PC: 2d1a9 | Set current PSP
2018-12-17T22:50:24.091881237Z 48 PC: 2d1ae | Get DOS version
2018-12-17T22:50:24.093672702Z 99 PC: 33990 | Get DBCS lead byte table pointer
2018-12-17T22:50:24.097198348Z 101 PC: 2d234 | Get extended country info
2018-12-17T22:50:24.09864424Z 99 PC: 2d23a | Get DBCS lead byte table pointer
2018-12-17T22:50:24.099776606Z 74 PC: 2d29c | Reallocate memory
2018-12-17T22:50:24.102039867Z 25 PC: 2d2d3 | Get default drive
2018-12-17T22:50:24.103445132Z 37 PC: 2cd93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:50:24.104739685Z 37 PC: 2cd9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:24.106343778Z 37 PC: 2cda1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:24.111497247Z 74 PC: 2bf3c | Reallocate memory
2018-12-17T22:50:24.113049286Z 72 PC: 2bf7d | Allocate memory
2018-12-17T22:50:24.115763455Z 72 PC: 2bfb5 | Allocate memory
2018-12-17T22:50:24.117686222Z 72 PC: 2bfbd | Allocate memory