Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Jeanluc.3855

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:28.575032827Z 53 PC: 132ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:28.576943685Z 53 PC: 132ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:59:28.578172914Z 53 PC: 132ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:28.579378899Z 53 PC: 132ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:28.581037053Z 53 PC: 132ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:28.584681242Z 53 PC: 132ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:28.586153904Z 53 PC: 132ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:59:28.587640826Z 53 PC: 132ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:59:28.592002724Z 53 PC: 132ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:59:28.593475777Z 53 PC: 132ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:59:28.595002629Z 53 PC: 132ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:59:28.596901986Z 53 PC: 132ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:59:28.598380307Z 53 PC: 132ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:59:28.599901103Z 53 PC: 132ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:59:28.605525216Z 53 PC: 132ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:59:28.606923033Z 53 PC: 132ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:59:28.608183327Z 53 PC: 132ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:59:28.610410254Z 53 PC: 132ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:28.612386855Z 53 PC: 132ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:59:28.614393646Z 37 PC: 132cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:28.616892522Z 37 PC: 132d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:28.622051927Z 37 PC: 132df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:28.623372536Z 37 PC: 132e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:28.627814125Z 68 PC: 13da8 | I/O control for devices (Set for = '')
2018-12-17T21:59:28.629462506Z 44 PC: 13edf | Get time 0x13edf: mov word ptr [0x3e], cx
0x13ee3: mov word ptr [0x40], dx
0x13ee7: retf
0x13ee8: mov bx, sp
0x13eea: mov al, byte ptr ss:[bx + 4]
0x13eee: cmp al, 0x61
0x13ef0: jb 0x13ef8
0x13ef2: cmp al, 0x7a
0x13ef4: ja 0x13ef8
0x13ef6: sub al, 0x20
0x13ef8: retf 2
0x13efb: mov di, 0x52
0x13efe: push ds
0x13eff: pop es
0x13f00: mov cx, 0x2a0
0x13f03: sub cx, di
0x13f05: shr cx, 1
0x13f07: xor ax, ax
0x13f09: cld
0x13f0a: rep stosd dword ptr es:[di], eax
2018-12-17T21:59:28.632327619Z 26 PC: 13205 | Set disk transfer address
2018-12-17T21:59:28.634689357Z 78 PC: 13211 | Find first file
2018-12-17T21:59:28.641100594Z 61 PC: 13980 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:28.648015255Z 48 PC: 13ace | Get DOS version
2018-12-17T21:59:28.65020335Z 61 PC: 13980 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:59:28.662866254Z 63 PC: 13a12 | Read file or device (Read 3855 bytes on handle 5)
2018-12-17T21:59:28.671007881Z 63 PC: 13a12 | Read file or device (Read 3855 bytes on handle 6)
2018-12-17T21:59:28.680087404Z 26 PC: 13229 | Set disk transfer address
2018-12-17T21:59:28.681548985Z 79 PC: 1322e | Find next file
2018-12-17T21:59:28.684355533Z 61 PC: 13980 | Open file (Filename = 'TEST.EXE')
2018-12-17T21:59:28.69168107Z 48 PC: 13ace | Get DOS version
2018-12-17T21:59:28.693547863Z 61 PC: 13980 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:59:28.700372142Z 63 PC: 13a12 | Read file or device (Read 3855 bytes on handle 7)
2018-12-17T21:59:28.708306948Z 63 PC: 13a12 | Read file or device (Read 3855 bytes on handle 8)
2018-12-17T21:59:28.716327767Z 64 PC: 136d8 | Write file or device (Write 26 bytes on handle 1)
2018-12-17T21:59:28.721659084Z 64 PC: 136d8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:59:28.723908075Z 37 PC: 13411 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:28.726228363Z 37 PC: 13411 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:59:28.727640825Z 37 PC: 13411 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:59:28.729030462Z 37 PC: 13411 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:28.731228469Z 37 PC: 13411 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:59:28.733134448Z 37 PC: 13411 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:28.734199772Z 37 PC: 13411 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:59:28.73613484Z 37 PC: 13411 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:59:28.73725134Z 37 PC: 13411 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:59:28.738329282Z 37 PC: 13411 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:59:28.740674461Z 37 PC: 13411 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:59:28.741878988Z 37 PC: 13411 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:59:28.742986166Z 37 PC: 13411 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:59:28.74466944Z 37 PC: 13411 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:59:28.745864252Z 37 PC: 13411 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:59:28.746970132Z 37 PC: 13411 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:59:28.754048763Z 37 PC: 13411 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:59:28.755438236Z 37 PC: 13411 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:59:28.758498469Z 37 PC: 13411 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:59:28.76076054Z 76 PC: 13450 | Terminate with return code (Return code = '0')