Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Team.6000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:01.68687824Z 53 PC: 1337a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:01.689322605Z 53 PC: 1337a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:01.690611728Z 53 PC: 1337a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:01.691918414Z 53 PC: 1337a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:01.69358655Z 53 PC: 1337a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:01.695236281Z 53 PC: 1337a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:01.696563025Z 53 PC: 1337a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:01.697886493Z 53 PC: 1337a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:01.700762839Z 53 PC: 1337a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:01.702186105Z 53 PC: 1337a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:01.703467684Z 53 PC: 1337a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:01.705603579Z 53 PC: 1337a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:01.707147481Z 53 PC: 1337a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:01.708594551Z 53 PC: 1337a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:01.711185191Z 53 PC: 1337a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:01.712495654Z 53 PC: 1337a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:01.71383931Z 53 PC: 1337a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:01.717822958Z 53 PC: 1337a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:01.727629652Z 53 PC: 1337a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:01.72903841Z 37 PC: 1338f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:01.730580008Z 37 PC: 13397 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:01.732083604Z 37 PC: 1339f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:01.733416229Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:01.73523112Z 68 PC: 13ed7 | I/O control for devices (Set for = '�r� �U')
2018-12-17T22:58:01.73715675Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:58:01.738617426Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:58:01.740436565Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:58:01.743130699Z 60 PC: 13a40 | Create or truncate file
2018-12-17T22:58:01.761001371Z 65 PC: 13b89 | Delete file (Filename = '�')
2018-12-17T22:58:01.772671067Z 26 PC: 13185 | Set disk transfer address
2018-12-17T22:58:01.774733244Z 78 PC: 13191 | Find first file
2018-12-17T22:58:01.782672848Z 26 PC: 13185 | Set disk transfer address
2018-12-17T22:58:01.78436584Z 78 PC: 13191 | Find first file
2018-12-17T22:58:01.791869676Z 86 PC: 13bcd | Rename file
2018-12-17T22:58:01.803893207Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:01.805255158Z 37 PC: 132fd | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:01.807622417Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:01.809036045Z 37 PC: 132fd | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:01.810356316Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:01.81239036Z 37 PC: 132fd | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:01.813803175Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:01.815151209Z 37 PC: 132fd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:01.8173964Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:01.8187906Z 37 PC: 132fd | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:01.820081367Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:01.821386119Z 37 PC: 132fd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:01.82321099Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:01.82484987Z 37 PC: 132fd | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:01.826346554Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:01.828798843Z 37 PC: 132fd | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:01.830132009Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:01.831466628Z 37 PC: 132fd | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:01.833592133Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:01.834965615Z 37 PC: 132fd | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:01.836252955Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:01.83831957Z 37 PC: 132fd | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:01.840008003Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:01.841699052Z 37 PC: 132fd | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:01.844195615Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:01.845614462Z 37 PC: 132fd | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:01.846787136Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:01.847989196Z 37 PC: 132fd | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:01.849797996Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:01.851289349Z 37 PC: 132fd | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:01.852691495Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:01.854858498Z 37 PC: 132fd | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:01.856441454Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:01.857789528Z 37 PC: 132fd | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:01.859662799Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:01.861026372Z 37 PC: 132fd | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:01.862370218Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:01.865236025Z 37 PC: 132fd | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:58:01.867103956Z 41 PC: 132ab | Parse filename
2018-12-17T22:58:01.868548913Z 41 PC: 132b9 | Parse filename
2018-12-17T22:58:01.870670621Z 75 PC: 132c4 | Execute program
2018-12-17T22:58:01.909112451Z 80 PC: 16449 | Set current PSP
2018-12-17T22:58:01.910418125Z 48 PC: 1644e | Get DOS version
2018-12-17T22:58:01.913449964Z 99 PC: 1cc30 | Get DBCS lead byte table pointer
2018-12-17T22:58:01.916481894Z 101 PC: 164d4 | Get extended country info
2018-12-17T22:58:01.918264705Z 99 PC: 164da | Get DBCS lead byte table pointer
2018-12-17T22:58:01.920293498Z 74 PC: 1653c | Reallocate memory
2018-12-17T22:58:01.922276456Z 25 PC: 16573 | Get default drive
2018-12-17T22:58:01.923819376Z 37 PC: 16033 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:58:01.925317612Z 37 PC: 1603a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:01.927036223Z 37 PC: 16041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:01.931425473Z 74 PC: 151dc | Reallocate memory
2018-12-17T22:58:01.93288143Z 72 PC: 1521d | Allocate memory
2018-12-17T22:58:01.937013087Z 72 PC: 15255 | Allocate memory
2018-12-17T22:58:01.939725996Z 72 PC: 1525d | Allocate memory