Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Hitohana

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:23.650333809Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:52:23.653119231Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:23.654777576Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:52:23.656631348Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:52:23.658546215Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:52:23.66144973Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:23.663463172Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:52:23.666179866Z 68 PC: 14092 | I/O control for devices (Set for = '��')
2018-12-17T22:52:23.669868415Z 68 PC: 14092 | I/O control for devices (Set for = '��')
2018-12-17T22:52:23.672762912Z 47 PC: 13e09 | Get disk transfer address
2018-12-17T22:52:23.674544899Z 26 PC: 13e12 | Set disk transfer address
2018-12-17T22:52:23.677332906Z 78 PC: 13e1c | Find first file
2018-12-17T22:52:23.684358534Z 26 PC: 13e25 | Set disk transfer address
2018-12-17T22:52:23.686505497Z 61 PC: 14345 | Open file (Filename = '7�>YY��')
2018-12-17T22:52:23.694121464Z 68 PC: 14036 | I/O control for devices (Set for = '� ��')
2018-12-17T22:52:23.696905945Z 68 PC: 14092 | I/O control for devices
2018-12-17T22:52:23.699572964Z 66 PC: 140b6 | Move file pointer
2018-12-17T22:52:23.701971189Z 63 PC: 1442e | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:52:23.711384853Z 62 PC: 13d85 | Close file
2018-12-17T22:52:23.714307684Z 61 PC: 14345 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:52:23.722607325Z 68 PC: 14036 | I/O control for devices (Set for = ' - shikaru bashoka ni ku shiet.')
2018-12-17T22:52:23.725747613Z 68 PC: 14092 | I/O control for devices
2018-12-17T22:52:23.728356765Z 61 PC: 14345 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:52:23.736254491Z 68 PC: 14036 | I/O control for devices (Set for = ' - shikaru bashoka ni ku shiet.')
2018-12-17T22:52:23.738536337Z 68 PC: 14092 | I/O control for devices
2018-12-17T22:52:23.741773248Z 66 PC: 13e73 | Move file pointer
2018-12-17T22:52:23.743624085Z 66 PC: 13e80 | Move file pointer
2018-12-17T22:52:23.745489229Z 66 PC: 13e8f | Move file pointer
2018-12-17T22:52:23.748422759Z 66 PC: 13e73 | Move file pointer
2018-12-17T22:52:23.751005701Z 66 PC: 13e80 | Move file pointer
2018-12-17T22:52:23.752924866Z 66 PC: 13e8f | Move file pointer
2018-12-17T22:52:23.755836265Z 67 PC: 13cad | Get or set file attributes
2018-12-17T22:52:23.762834301Z 87 PC: 1400e | Get or set file date and time
2018-12-17T22:52:23.764959103Z 62 PC: 13d85 | Close file
2018-12-17T22:52:23.768329935Z 67 PC: 13cad | Get or set file attributes
2018-12-17T22:52:23.785986533Z 65 PC: 14511 | Delete file (Filename = 'TEST.EXE')
2018-12-17T22:52:23.800466282Z 67 PC: 13cad | Get or set file attributes
2018-12-17T22:52:23.808505344Z 60 PC: 141d2 | Create or truncate file
2018-12-17T22:52:23.825773622Z 68 PC: 14092 | I/O control for devices (Set for = '��')
2018-12-17T22:52:23.828446764Z 63 PC: 1442e | Read file or device (Read 8704 bytes on handle 5)
2018-12-17T22:52:23.842972311Z 81 PC: 122cc | Get current PSP
2018-12-17T22:52:23.844801918Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:52:23.847017159Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:52:23.850848536Z 89 PC: 12459 | Get extended error info
2018-12-17T22:52:23.853096478Z 2 PC: 1268d | Character output (Char = '53')
2018-12-17T22:52:23.856434329Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:52:23.859217247Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:52:23.869270312Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:52:23.871842814Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:52:23.87384788Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:52:23.876153531Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:23.878159149Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:52:23.87994838Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:52:23.882694459Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:52:23.884492466Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:23.886761559Z 2 PC: 1268d | Character output (Char = '66')
2018-12-17T22:52:23.888909504Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:52:23.89213886Z 2 PC: 1268d | Character output (Char = '75')
2018-12-17T22:52:23.895298275Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:52:23.897957149Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:52:23.901894315Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:23.904732136Z 2 PC: 126da | Character output (Char = '72')
2018-12-17T22:52:23.907399016Z 2 PC: 126da | Character output (Char = '65')
2018-12-17T22:52:23.910737227Z 2 PC: 126da | Character output (Char = '61')
2018-12-17T22:52:23.913207598Z 2 PC: 126da | Character output (Char = '64')
2018-12-17T22:52:23.916116202Z 2 PC: 126da | Character output (Char = '69')
2018-12-17T22:52:23.919966414Z 2 PC: 126da | Character output (Char = '6e')
2018-12-17T22:52:23.922388934Z 2 PC: 126da | Character output (Char = '67')
2018-12-17T22:52:23.925012373Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:23.928351295Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:52:23.931154631Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:52:23.933929724Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:52:23.937782983Z 2 PC: 1268d | Character output (Char = '76')
2018-12-17T22:52:23.940455423Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:52:23.943142601Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:23.945803258Z 2 PC: 126ce | Character output (Char = '41')
2018-12-17T22:52:23.95039281Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:52:23.953617417Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:52:23.957890875Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:52:23.961413833Z 2 PC: 1268d | Character output (Char = '62')
2018-12-17T22:52:23.963992557Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:52:23.966537618Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:52:23.970242437Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:52:23.973244817Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:52:23.975788275Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:23.979206637Z 2 PC: 1268d | Character output (Char = '52')
2018-12-17T22:52:23.982329744Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:52:23.986503745Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:52:23.989236228Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:52:23.992063829Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:52:23.99493892Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:52:23.997700638Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:24.000985969Z 2 PC: 1268d | Character output (Char = '49')
2018-12-17T22:52:24.003626319Z 2 PC: 1268d | Character output (Char = '67')
2018-12-17T22:52:24.005989448Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:52:24.009117264Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:52:24.011690017Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:52:24.014388065Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:52:24.017475244Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:52:24.021185534Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:52:24.023745202Z 2 PC: 1268d | Character output (Char = '46')
2018-12-17T22:52:24.027105284Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:52:24.030040739Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:52:24.032554802Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:52:24.036692794Z 2 PC: 1268d | Character output (Char = '3f')
2018-12-17T22:52:24.039398246Z 12 PC: 12581 | Flush input buffer and input