Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Oxbo.3744

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:21.756692282Z 53 PC: 12cba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:21.758554026Z 53 PC: 12cba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:21.761668242Z 53 PC: 12cba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:21.763830669Z 53 PC: 12cba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:21.76564157Z 53 PC: 12cba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:21.768095266Z 53 PC: 12cba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:21.769638596Z 53 PC: 12cba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:21.774167023Z 53 PC: 12cba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:21.778807342Z 53 PC: 12cba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:21.787374601Z 53 PC: 12cba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:21.801572539Z 53 PC: 12cba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:21.804100084Z 53 PC: 12cba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:21.80592111Z 53 PC: 12cba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:21.807677623Z 53 PC: 12cba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:21.80946266Z 53 PC: 12cba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:21.811986425Z 53 PC: 12cba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:21.813557654Z 53 PC: 12cba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:21.81984041Z 53 PC: 12cba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:21.822186376Z 53 PC: 12cba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:21.823954662Z 37 PC: 12ccf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:21.825669322Z 37 PC: 12cd7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:21.827891588Z 37 PC: 12cdf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:21.829635883Z 37 PC: 12ce7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:21.831482767Z 68 PC: 13a41 | I/O control for devices (Set for = '�')
2018-12-17T22:56:21.833763633Z 48 PC: 13767 | Get DOS version
2018-12-17T22:56:21.835543956Z 61 PC: 13619 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:56:21.8434627Z 63 PC: 136ec | Read file or device (Read 3744 bytes on handle 5)
2018-12-17T22:56:21.871946211Z 62 PC: 13669 | Close file
2018-12-17T22:56:21.874726296Z 26 PC: 12c05 | Set disk transfer address
2018-12-17T22:56:21.877099249Z 78 PC: 12c11 | Find first file
2018-12-17T22:56:21.885473669Z 61 PC: 13619 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:21.893608049Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:21.901895452Z 62 PC: 13669 | Close file
2018-12-17T22:56:21.904695081Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:21.926144838Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:21.941841597Z 62 PC: 13669 | Close file
2018-12-17T22:56:21.951059707Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:21.952521515Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:21.955962113Z 61 PC: 13619 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:21.963954574Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:21.971101398Z 62 PC: 13669 | Close file
2018-12-17T22:56:21.972765684Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:21.984618694Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:21.994351186Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.007314963Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:22.008994831Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:22.013545257Z 61 PC: 13619 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:22.021225345Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:22.029864836Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.032938656Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:22.048036083Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:22.057654568Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.068138393Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:22.069653419Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:22.073357855Z 61 PC: 13619 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:56:22.081207058Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:22.089171652Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.091453399Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:22.106232368Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:22.116721687Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.126429102Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:22.128627388Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:22.133790769Z 61 PC: 13619 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:56:22.141832769Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:22.149671758Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.152989632Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:22.167861378Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:22.178425568Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.18959982Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:22.191453293Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:22.19542119Z 61 PC: 13619 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:22.203473375Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:22.213068013Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.215712253Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:22.229919415Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:22.242109114Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.251419729Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:22.253091434Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:22.258000645Z 61 PC: 13619 | Open file (Filename = 'PAH.COM')
2018-12-17T22:56:22.265834862Z 63 PC: 136ec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:56:22.270373174Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.27250245Z 60 PC: 13619 | Create or truncate file
2018-12-17T22:56:22.280983758Z 64 PC: 136ec | Write file or device (Write 3744 bytes on handle 5)
2018-12-17T22:56:22.289788478Z 62 PC: 13669 | Close file
2018-12-17T22:56:22.298993746Z 26 PC: 12c29 | Set disk transfer address
2018-12-17T22:56:22.301346816Z 79 PC: 12c2e | Find next file
2018-12-17T22:56:22.305237045Z 64 PC: 132e0 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:56:22.310523554Z 64 PC: 132e0 | Write file or device (Write 39 bytes on handle 1)
2018-12-17T22:56:22.31822109Z 64 PC: 132e0 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:56:22.323742191Z 64 PC: 132e0 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:56:22.326041675Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:22.328641412Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:22.330264414Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:22.331876777Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:22.334478052Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:22.336141129Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:22.337793432Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:22.339605751Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:22.342024604Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:22.34378296Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:22.345404582Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:22.347685709Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:22.350596531Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:22.351902243Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:22.354018099Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:22.355656612Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:22.357273918Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:22.359489731Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:22.361109625Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:22.36272442Z 76 PC: 12e50 | Terminate with return code (Return code = '0')