Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Pish.6208

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:36.21271717Z 53 PC: 1336a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:36.214344838Z 53 PC: 1336a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:36.216149378Z 53 PC: 1336a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:36.21783817Z 53 PC: 1336a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:36.219517976Z 53 PC: 1336a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:36.223524182Z 53 PC: 1336a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:36.225055549Z 53 PC: 1336a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:36.227106381Z 53 PC: 1336a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:36.229465042Z 53 PC: 1336a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:36.231037826Z 53 PC: 1336a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:36.233165153Z 53 PC: 1336a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:36.236944844Z 53 PC: 1336a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:36.238414254Z 53 PC: 1336a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:36.239980847Z 53 PC: 1336a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:36.242167836Z 53 PC: 1336a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:36.243899859Z 53 PC: 1336a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:36.245496819Z 53 PC: 1336a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:36.247100241Z 53 PC: 1336a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:36.258872376Z 53 PC: 1336a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:36.260866812Z 37 PC: 1337f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:36.262846511Z 37 PC: 13387 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:36.267838599Z 37 PC: 1338f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:36.27314095Z 37 PC: 13397 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:36.275389885Z 68 PC: 13ec7 | I/O control for devices (Set for = '�&�+�=')
2018-12-17T22:51:36.278120836Z 48 PC: 13bf2 | Get DOS version
2018-12-17T22:51:36.281325125Z 61 PC: 13a30 | Open file (Filename = 'c:\dos\smartdrv.exe')
2018-12-17T22:51:36.29214973Z 26 PC: 1322f | Set disk transfer address
2018-12-17T22:51:36.293967284Z 78 PC: 1323b | Find first file
2018-12-17T22:51:36.302223413Z 67 PC: 131b8 | Get or set file attributes
2018-12-17T22:51:36.32013406Z 61 PC: 13a30 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:51:36.327856467Z 87 PC: 131d2 | Get or set file date and time
2018-12-17T22:51:36.330763137Z 62 PC: 13a80 | Close file
2018-12-17T22:51:36.333052708Z 26 PC: 13253 | Set disk transfer address
2018-12-17T22:51:36.334521798Z 79 PC: 13258 | Find next file
2018-12-17T22:51:36.339016902Z 67 PC: 131b8 | Get or set file attributes
2018-12-17T22:51:36.350272136Z 61 PC: 13a30 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:51:36.358074834Z 87 PC: 131d2 | Get or set file date and time
2018-12-17T22:51:36.360964192Z 62 PC: 13a80 | Close file
2018-12-17T22:51:36.363488224Z 26 PC: 13253 | Set disk transfer address
2018-12-17T22:51:36.365329102Z 79 PC: 13258 | Find next file
2018-12-17T22:51:36.369876775Z 67 PC: 131b8 | Get or set file attributes
2018-12-17T22:51:36.385993361Z 61 PC: 13a30 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:51:36.395290165Z 87 PC: 131d2 | Get or set file date and time
2018-12-17T22:51:36.398245237Z 62 PC: 13a80 | Close file
2018-12-17T22:51:36.400715337Z 26 PC: 13253 | Set disk transfer address
2018-12-17T22:51:36.402302319Z 79 PC: 13258 | Find next file
2018-12-17T22:51:36.405688309Z 67 PC: 131b8 | Get or set file attributes
2018-12-17T22:51:36.4171393Z 61 PC: 13a30 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:51:36.424667452Z 87 PC: 131d2 | Get or set file date and time
2018-12-17T22:51:36.427213555Z 64 PC: 13788 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:51:36.429959133Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:36.431359323Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:36.433820216Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:36.436324561Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:36.437760419Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:36.439183733Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:36.441605662Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:36.443293513Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:36.444951678Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:36.447268821Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:36.44906226Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:36.450886607Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:36.452701106Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:36.455779388Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:36.45847374Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:36.460256298Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:36.465678835Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:36.469188027Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:36.473161531Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:36.475655928Z 76 PC: 13500 | Terminate with return code (Return code = '1')