Sample viewer

vx.netlux.org/Virus.DOS.Helloween.1376.h

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:45.82146407Z 236 PC: 1340d | UNKNOWN!
2018-12-17T22:54:45.823781498Z 53 PC: 134dc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:45.825499633Z 37 PC: 134f4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:45.827528612Z 53 PC: 12aea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:45.829309164Z 53 PC: 12aea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:45.830843652Z 53 PC: 12aea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:45.832199593Z 53 PC: 12aea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:45.833572028Z 53 PC: 12aea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.83561682Z 53 PC: 12aea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:45.836898453Z 53 PC: 12aea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:45.838188502Z 53 PC: 12aea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:45.840380333Z 53 PC: 12aea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:45.84202907Z 53 PC: 12aea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:45.843711788Z 53 PC: 12aea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:45.846703982Z 53 PC: 12aea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:45.848409592Z 53 PC: 12aea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:45.850080285Z 53 PC: 12aea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:45.852737137Z 53 PC: 12aea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:45.854413013Z 53 PC: 12aea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:45.855886014Z 53 PC: 12aea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:45.857369137Z 53 PC: 12aea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:45.859742251Z 37 PC: 12aff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:45.861670949Z 37 PC: 12b07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:45.863222862Z 37 PC: 12b0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.865284378Z 37 PC: 12b17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:45.867190548Z 68 PC: 13175 | I/O control for devices (Set for = '�n$P3�&���t&�&�>�t��&�')
2018-12-17T22:54:45.86905617Z 64 PC: 12f08 | Write file or device (Write 13 bytes on handle 1)
2018-12-17T22:54:45.8812503Z 64 PC: 12f08 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:54:45.883489523Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:45.885318798Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:45.894766772Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:45.896148417Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:45.8978757Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:45.900477255Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:45.901780373Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:45.903284679Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:45.905743772Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:45.907353765Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:45.908807552Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:45.911178838Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:45.912704825Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:45.914126365Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:45.916128272Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:45.917368663Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:45.918937038Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:45.921503454Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:45.923969357Z 76 PC: 12c80 | Terminate with return code (Return code = '0')