Sample viewer

vx.netlux.org/Virus.DOS.HLLO.DPOG.4368

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:16.054536101Z 53 PC: 12eda | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:16.057024882Z 53 PC: 12eda | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:16.059151176Z 53 PC: 12eda | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:16.061936353Z 53 PC: 12eda | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:16.064328938Z 53 PC: 12eda | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:16.066678918Z 53 PC: 12eda | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:16.069063238Z 53 PC: 12eda | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:16.071442835Z 53 PC: 12eda | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:16.074117781Z 53 PC: 12eda | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:16.07642213Z 53 PC: 12eda | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:16.078144534Z 53 PC: 12eda | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:16.07999738Z 53 PC: 12eda | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:16.10209548Z 53 PC: 12eda | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:16.103595282Z 53 PC: 12eda | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:16.104971087Z 53 PC: 12eda | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:16.106945262Z 53 PC: 12eda | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:16.108708271Z 53 PC: 12eda | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:16.110384274Z 53 PC: 12eda | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:16.112251106Z 53 PC: 12eda | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:16.114049042Z 37 PC: 12eef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:16.115267191Z 37 PC: 12ef7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:16.116449323Z 37 PC: 12eff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:16.118071878Z 37 PC: 12f07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:16.119782216Z 68 PC: 1396d | I/O control for devices (Set for = '')
2018-12-17T22:53:16.121588514Z 48 PC: 13693 | Get DOS version
2018-12-17T22:53:16.124466964Z 61 PC: 13545 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:16.132068651Z 63 PC: 13618 | Read file or device (Read 4368 bytes on handle 5)
2018-12-17T22:53:16.140536509Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.143674122Z 26 PC: 12e27 | Set disk transfer address
2018-12-17T22:53:16.144974869Z 78 PC: 12e33 | Find first file
2018-12-17T22:53:16.153174172Z 61 PC: 13545 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:53:16.161360868Z 66 PC: 13677 | Move file pointer
2018-12-17T22:53:16.163715275Z 63 PC: 13618 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:53:16.1669924Z 63 PC: 13618 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:53:16.170546289Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.172915819Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:53:16.179535411Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:53:16.197431979Z 61 PC: 13545 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:53:16.20655587Z 64 PC: 13618 | Write file or device (Write 4368 bytes on handle 5)
2018-12-17T22:53:16.216645984Z 66 PC: 13677 | Move file pointer
2018-12-17T22:53:16.221974173Z 64 PC: 13618 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:53:16.232014195Z 64 PC: 13618 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:53:16.235494298Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.245162977Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:53:16.257834738Z 26 PC: 12e4b | Set disk transfer address
2018-12-17T22:53:16.25989784Z 79 PC: 12e50 | Find next file
2018-12-17T22:53:16.263196904Z 26 PC: 12e27 | Set disk transfer address
2018-12-17T22:53:16.265705028Z 78 PC: 12e33 | Find first file
2018-12-17T22:53:16.274266768Z 61 PC: 13545 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:16.282841165Z 66 PC: 13677 | Move file pointer
2018-12-17T22:53:16.284675156Z 63 PC: 13618 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:53:16.294290174Z 63 PC: 13618 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:53:16.297598959Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.300354177Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:53:16.308616912Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:53:16.320399053Z 61 PC: 13545 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:16.328545123Z 64 PC: 13618 | Write file or device (Write 4368 bytes on handle 5)
2018-12-17T22:53:16.340062637Z 66 PC: 13677 | Move file pointer
2018-12-17T22:53:16.343049175Z 64 PC: 13618 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:53:16.350959569Z 64 PC: 13618 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:53:16.355970376Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.365120843Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:53:16.375806761Z 26 PC: 12e4b | Set disk transfer address
2018-12-17T22:53:16.377412278Z 79 PC: 12e50 | Find next file
2018-12-17T22:53:16.381709709Z 61 PC: 13545 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:53:16.387424482Z 66 PC: 13677 | Move file pointer
2018-12-17T22:53:16.388672555Z 63 PC: 13618 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:53:16.39545519Z 63 PC: 13618 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:53:16.398128819Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.400546124Z 67 PC: 12dcf | Get or set file attributes
2018-12-17T22:53:16.40785643Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:53:16.420123249Z 61 PC: 13545 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:53:16.42491114Z 64 PC: 13618 | Write file or device (Write 4368 bytes on handle 5)
2018-12-17T22:53:16.431615865Z 66 PC: 13677 | Move file pointer
2018-12-17T22:53:16.433362737Z 64 PC: 13618 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:53:16.439754251Z 64 PC: 13618 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:53:16.442377655Z 62 PC: 13595 | Close file
2018-12-17T22:53:16.450197177Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:53:16.459453443Z 26 PC: 12e4b | Set disk transfer address
2018-12-17T22:53:16.461547783Z 79 PC: 12e50 | Find next file
2018-12-17T22:53:16.465533049Z 64 PC: 1329d | Write file or device (Write 25 bytes on handle 1)
2018-12-17T22:53:16.471440046Z 64 PC: 1329d | Write file or device (Write 25 bytes on handle 1)
2018-12-17T22:53:16.477356338Z 64 PC: 1329d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:53:16.479625575Z 37 PC: 13031 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:16.481154948Z 37 PC: 13031 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:16.484156547Z 37 PC: 13031 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:16.485553825Z 37 PC: 13031 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:16.487646619Z 37 PC: 13031 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:16.488843211Z 37 PC: 13031 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:16.494648846Z 37 PC: 13031 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:16.496061398Z 37 PC: 13031 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:16.497446487Z 37 PC: 13031 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:16.499410189Z 37 PC: 13031 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:16.50078337Z 37 PC: 13031 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:16.502142388Z 37 PC: 13031 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:16.504098553Z 37 PC: 13031 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:16.505452735Z 37 PC: 13031 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:16.506820195Z 37 PC: 13031 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:16.509032444Z 37 PC: 13031 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:16.510280705Z 37 PC: 13031 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:16.51173147Z 37 PC: 13031 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:16.513819254Z 37 PC: 13031 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:16.515364828Z 76 PC: 13070 | Terminate with return code (Return code = '0')