Sample viewer

vx.netlux.org/Virus.DOS.HLLO.VsW.3836

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:13.443270335Z 53 PC: 130fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:13.444439058Z 53 PC: 130fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:13.445901161Z 53 PC: 130fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:13.447076491Z 53 PC: 130fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:13.448352348Z 53 PC: 130fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:13.450087633Z 53 PC: 130fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:13.451269019Z 53 PC: 130fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:13.452582815Z 53 PC: 130fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:13.45427132Z 53 PC: 130fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:13.455522188Z 53 PC: 130fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:13.456711832Z 53 PC: 130fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:13.458296462Z 53 PC: 130fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:13.459719942Z 53 PC: 130fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:13.461151794Z 53 PC: 130fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:13.46246464Z 53 PC: 130fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:13.468152473Z 53 PC: 130fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:13.469525442Z 53 PC: 130fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:13.47089025Z 53 PC: 130fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:13.473247371Z 53 PC: 130fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:13.475470972Z 37 PC: 1310f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:13.477296612Z 37 PC: 13117 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:13.478965485Z 37 PC: 1311f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:13.480099907Z 37 PC: 13127 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:13.481689773Z 68 PC: 13aba | I/O control for devices (Set for = '����')
2018-12-17T22:55:13.483990382Z 26 PC: 12ff4 | Set disk transfer address
2018-12-17T22:55:13.485476988Z 78 PC: 12fe7 | Find first file
2018-12-17T22:55:13.492124799Z 48 PC: 137e0 | Get DOS version
2018-12-17T22:55:13.494936236Z 26 PC: 13016 | Set disk transfer address
2018-12-17T22:55:13.496162339Z 79 PC: 1301b | Find next file
2018-12-17T22:55:13.4989765Z 64 PC: 13518 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:55:13.501510891Z 37 PC: 13251 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:13.503874811Z 37 PC: 13251 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:13.506185703Z 37 PC: 13251 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:13.51395743Z 37 PC: 13251 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:13.515323562Z 37 PC: 13251 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:13.516697094Z 37 PC: 13251 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:13.518937696Z 37 PC: 13251 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:13.520670855Z 37 PC: 13251 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:13.522069681Z 37 PC: 13251 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:13.523594826Z 37 PC: 13251 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:13.525778692Z 37 PC: 13251 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:13.527247838Z 37 PC: 13251 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:13.528746671Z 37 PC: 13251 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:13.531893274Z 37 PC: 13251 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:13.53358275Z 37 PC: 13251 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:13.535278894Z 37 PC: 13251 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:13.539680943Z 37 PC: 13251 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:13.541191332Z 37 PC: 13251 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:13.542593711Z 37 PC: 13251 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:13.544951319Z 76 PC: 13290 | Terminate with return code (Return code = '0')