Sample viewer

vx.netlux.org/Virus.DOS.HLLO.4285

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:53.28820666Z 53 PC: 12dea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:53.290371293Z 53 PC: 12dea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:53.291589403Z 53 PC: 12dea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:53.293104405Z 53 PC: 12dea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:53.294606509Z 53 PC: 12dea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:53.296994101Z 53 PC: 12dea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:53.298276649Z 53 PC: 12dea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:53.299499824Z 53 PC: 12dea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:53.30732206Z 53 PC: 12dea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:53.308553126Z 53 PC: 12dea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:53.309732885Z 53 PC: 12dea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:53.311998525Z 53 PC: 12dea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:53.313598963Z 53 PC: 12dea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:53.315237071Z 53 PC: 12dea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:53.317150072Z 53 PC: 12dea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:53.318441922Z 53 PC: 12dea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:53.319659536Z 53 PC: 12dea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:53.32108353Z 53 PC: 12dea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:53.322564938Z 53 PC: 12dea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:53.323800287Z 37 PC: 12dff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:53.325445231Z 37 PC: 12e07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:53.32717683Z 37 PC: 12e0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:53.328169714Z 37 PC: 12e17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:53.3292756Z 68 PC: 13b3b | I/O control for devices (Set for = '��-�l@ B@�\&��')
2018-12-17T22:50:53.331004061Z 48 PC: 13861 | Get DOS version
2018-12-17T22:50:53.332173106Z 61 PC: 13713 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:50:53.337128474Z 63 PC: 137e6 | Read file or device (Read 4868 bytes on handle 5)
2018-12-17T22:50:53.342600919Z 64 PC: 1346b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:50:53.343932814Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:53.345143611Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:53.346970536Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:53.347963871Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:53.348913346Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:53.350409676Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:53.351741111Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:53.352883818Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:53.356527418Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:53.357900611Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:53.359174606Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:53.361135884Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:53.36248779Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:53.363727411Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:53.365434647Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:53.366848595Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:53.368104199Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:53.369400351Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:53.371034648Z 37 PC: 12f41 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:53.372189495Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.374221386Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.376803847Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.378959707Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.381098488Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.383770722Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.386248175Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.388436039Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.3910393Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.393390207Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.396081074Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.398881146Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.401115054Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.403544367Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.406477141Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.409107443Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.411602492Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.415185039Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.417580972Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.419784326Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.424091385Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.426536639Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.43326271Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.435786415Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.438501857Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.440723317Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.443001533Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.4457456Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.448553431Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.451323903Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.454356275Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.456739578Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.45879056Z 6 PC: 12fc8 | Direct console I/O
2018-12-17T22:50:53.463370694Z 76 PC: 12f80 | Terminate with return code (Return code = '100')