Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Gotovo.5488

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:27.504752761Z 53 PC: 131aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:27.512355009Z 53 PC: 131aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:27.513535587Z 53 PC: 131aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:27.514690431Z 53 PC: 131aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:27.516269249Z 53 PC: 131aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:27.517312945Z 53 PC: 131aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:27.518215001Z 53 PC: 131aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:27.519768172Z 53 PC: 131aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:27.520786027Z 53 PC: 131aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:27.521754489Z 53 PC: 131aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:27.523693761Z 53 PC: 131aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:27.524706461Z 53 PC: 131aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:27.525670529Z 53 PC: 131aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:27.527074298Z 53 PC: 131aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:27.528635149Z 53 PC: 131aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:27.530233657Z 53 PC: 131aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:27.531835227Z 53 PC: 131aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:27.533561618Z 53 PC: 131aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:27.535166693Z 53 PC: 131aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:27.536842069Z 37 PC: 131bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:27.565563378Z 37 PC: 131c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:27.567980679Z 37 PC: 131cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:27.570623441Z 37 PC: 131d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:27.572538547Z 68 PC: 13d28 | I/O control for devices (Set for = '')
2018-12-17T22:01:27.575813595Z 64 PC: 135c8 | Write file or device (Write 10 bytes on handle 1)
2018-12-17T22:01:27.581130026Z 26 PC: 130f5 | Set disk transfer address
2018-12-17T22:01:27.582346312Z 78 PC: 13101 | Find first file
2018-12-17T22:01:27.590807072Z 64 PC: 135c8 | Write file or device (Write 10 bytes on handle 1)
2018-12-17T22:01:27.59569309Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:27.597474916Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:27.605528643Z 61 PC: 13900 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:01:27.616117239Z 64 PC: 135c8 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:01:27.619448292Z 64 PC: 135c8 | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:01:27.624816294Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T22:01:27.627811384Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T22:01:27.630569828Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.633115798Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.635087507Z 64 PC: 135c8 | Write file or device (Write 23 bytes on handle 1)
2018-12-17T22:01:27.640533043Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.642091534Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.648022517Z 26 PC: 130f5 | Set disk transfer address
2018-12-17T22:01:27.649441816Z 78 PC: 13101 | Find first file
2018-12-17T22:01:27.655165163Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.664396215Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.671139939Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.672398265Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.67553078Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.677029926Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.680693681Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.682246648Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.685339373Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.686878126Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.690839123Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.69234571Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.695653871Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.698345958Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.700903138Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.701924925Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.705013127Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.706225328Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.709272181Z 64 PC: 135c8 | Write file or device (Write 10 bytes on handle 1)
2018-12-17T22:01:27.71443476Z 26 PC: 130f5 | Set disk transfer address
2018-12-17T22:01:27.715745578Z 78 PC: 13101 | Find first file
2018-12-17T22:01:27.725991953Z 64 PC: 135c8 | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:01:27.731453534Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:27.735409356Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:27.742474049Z 61 PC: 13900 | Open file (Filename = '\SLEEP.COM')
2018-12-17T22:01:27.750060573Z 64 PC: 135c8 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:01:27.753288037Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:27.758038814Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T22:01:27.76216717Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T22:01:27.768929386Z 64 PC: 135c8 | Write file or device (Write 20 bytes on handle 1)
2018-12-17T22:01:27.773791996Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.776829159Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.779142634Z 64 PC: 135c8 | Write file or device (Write 16 bytes on handle 1)
2018-12-17T22:01:27.785290407Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:27.787739034Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:27.796158855Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:27.801404452Z 61 PC: 13900 | Open file (Filename = '\SLEEP.COM')
2018-12-17T22:01:27.808245086Z 63 PC: 139d3 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T22:01:27.815921683Z 64 PC: 139d3 | Write file or device (Write 5488 bytes on handle 6)
2018-12-17T22:01:27.833099518Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.835645077Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.843993118Z 64 PC: 135c8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:01:27.848676658Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.85060343Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.861145269Z 64 PC: 135c8 | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:01:27.866183478Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:27.868506022Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:27.876089656Z 61 PC: 13900 | Open file (Filename = '\PRINT.COM')
2018-12-17T22:01:27.883639153Z 64 PC: 135c8 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:01:27.888629504Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:27.893409515Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T22:01:27.896371226Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T22:01:27.903868841Z 64 PC: 135c8 | Write file or device (Write 20 bytes on handle 1)
2018-12-17T22:01:27.909888056Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.911719323Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.91980902Z 64 PC: 135c8 | Write file or device (Write 16 bytes on handle 1)
2018-12-17T22:01:27.924886054Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:27.926346278Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:27.933854271Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:27.938651926Z 61 PC: 13900 | Open file (Filename = '\PRINT.COM')
2018-12-17T22:01:27.949046881Z 63 PC: 139d3 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T22:01:27.956985648Z 64 PC: 139d3 | Write file or device (Write 5488 bytes on handle 6)
2018-12-17T22:01:27.965583481Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.967610378Z 62 PC: 13950 | Close file
2018-12-17T22:01:27.983033888Z 64 PC: 135c8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:01:27.987771915Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:27.989079996Z 79 PC: 1311e | Find next file
2018-12-17T22:01:27.993091453Z 64 PC: 135c8 | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:01:27.998351252Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:28.000057999Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:28.007695149Z 61 PC: 13900 | Open file (Filename = '\HELLO.COM')
2018-12-17T22:01:28.015654605Z 64 PC: 135c8 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:01:28.018921069Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:28.025634438Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T22:01:28.033093563Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T22:01:28.039987511Z 64 PC: 135c8 | Write file or device (Write 20 bytes on handle 1)
2018-12-17T22:01:28.045001019Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.047959073Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.050316319Z 64 PC: 135c8 | Write file or device (Write 16 bytes on handle 1)
2018-12-17T22:01:28.056324316Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:28.058961441Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:28.066125481Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:28.071031822Z 61 PC: 13900 | Open file (Filename = '\HELLO.COM')
2018-12-17T22:01:28.079493924Z 63 PC: 139d3 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T22:01:28.087002541Z 64 PC: 139d3 | Write file or device (Write 5488 bytes on handle 6)
2018-12-17T22:01:28.103536515Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.106798353Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.115369946Z 64 PC: 135c8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:01:28.120094176Z 26 PC: 13119 | Set disk transfer address
2018-12-17T22:01:28.124705688Z 79 PC: 1311e | Find next file
2018-12-17T22:01:28.128302664Z 64 PC: 135c8 | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:01:28.13449803Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:28.136977036Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:28.146727279Z 61 PC: 13900 | Open file (Filename = '\PHANG.COM')
2018-12-17T22:01:28.155980689Z 64 PC: 135c8 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:01:28.16005743Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:28.165186821Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T22:01:28.168144125Z 63 PC: 139d3 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T22:01:28.195140277Z 64 PC: 135c8 | Write file or device (Write 20 bytes on handle 1)
2018-12-17T22:01:28.200620466Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.203578567Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.206251898Z 64 PC: 135c8 | Write file or device (Write 16 bytes on handle 1)
2018-12-17T22:01:28.212266716Z 48 PC: 13a4e | Get DOS version
2018-12-17T22:01:28.214021721Z 61 PC: 13900 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:28.223226273Z 64 PC: 135c8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:01:28.23040656Z 61 PC: 13900 | Open file (Filename = '\PHANG.COM')
2018-12-17T22:01:28.237277449Z 63 PC: 139d3 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T22:01:28.244706874Z 64 PC: 139d3 | Write file or device (Write 5488 bytes on handle 6)
2018-12-17T22:01:28.258665236Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.260867306Z 62 PC: 13950 | Close file
2018-12-17T22:01:28.269817356Z 64 PC: 135c8 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T22:01:28.277075666Z 64 PC: 135c8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:01:28.279059821Z 37 PC: 13301 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:28.280318578Z 37 PC: 13301 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:28.282109869Z 37 PC: 13301 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:28.283192735Z 37 PC: 13301 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:28.284256842Z 37 PC: 13301 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:28.286062373Z 37 PC: 13301 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:28.287111284Z 37 PC: 13301 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:28.288160998Z 37 PC: 13301 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:28.289883914Z 37 PC: 13301 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:28.290929404Z 37 PC: 13301 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:28.29198994Z 37 PC: 13301 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:28.29402604Z 37 PC: 13301 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:28.295072459Z 37 PC: 13301 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:28.296096Z 37 PC: 13301 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:28.297718005Z 37 PC: 13301 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:28.298774303Z 37 PC: 13301 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:28.299995124Z 37 PC: 13301 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:28.301638622Z 37 PC: 13301 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:28.303060024Z 37 PC: 13301 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:28.304947508Z 76 PC: 13340 | Terminate with return code (Return code = '0')