Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Kat

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:50.802620217Z 48 PC: 1abfc | Get DOS version
2018-12-17T22:58:50.805246053Z 74 PC: 1ac4c | Reallocate memory
2018-12-17T22:58:50.806956698Z 48 PC: 1acb0 | Get DOS version
2018-12-17T22:58:50.808023974Z 53 PC: 1acb8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:50.809818567Z 37 PC: 1acca | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:50.811301223Z 53 PC: 1daa2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:50.812462856Z 37 PC: 1dab2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:50.814376904Z 53 PC: 1dab7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:50.815635109Z 37 PC: 1dac7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:50.816853479Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:50.818951963Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:50.821220176Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:50.823349017Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:50.826576012Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:50.828367569Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:50.830114863Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:50.832005136Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:50.834139938Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:50.835761256Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:50.837358308Z 53 PC: 1b7f6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:50.841656547Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:50.84329169Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:50.844809633Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:50.847622069Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:50.849582343Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:50.850888508Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:50.853741661Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:50.856248572Z 37 PC: 1b825 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:50.857921346Z 37 PC: 1b82c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:50.860392891Z 37 PC: 1b831 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:50.86197744Z 68 PC: 1ad5b | I/O control for devices (Set for = '�4c8��P��L8�4c8�P��L8�4c8�0P��L8�4c8�HP��L8�4c8�bP��L8�4c8�zP�')
2018-12-17T22:58:50.863498699Z 68 PC: 1ad5b | I/O control for devices (Set for = ' �t���ꡚ')
2018-12-17T22:58:50.865840831Z 68 PC: 1ad5b | I/O control for devices (Set for = 'G')
2018-12-17T22:58:50.871041626Z 68 PC: 1ad5b | I/O control for devices (Set for = '�,N��3ɬ:�t ���A��,tN�ـ�,uN��O� :����tA�')
2018-12-17T22:58:50.872889268Z 68 PC: 1ad5b | I/O control for devices (Set for = '�,N��3ɬ:�t ���A��,tN�ـ�,uN��O� :����tA�')
2018-12-17T22:58:50.875843891Z 53 PC: 17b2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:50.877505665Z 53 PC: 17b37 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:50.879346094Z 53 PC: 17b44 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:50.88195656Z 37 PC: 17b59 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:50.883735765Z 37 PC: 17b61 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:50.885320393Z 37 PC: 17b69 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:50.887083808Z 53 PC: 185e8 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:50.889108934Z 53 PC: 185f5 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:58:50.890839627Z 53 PC: 18604 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:50.89249631Z 37 PC: 18611 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:50.894383187Z 53 PC: 18618 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:50.895660357Z 37 PC: 18625 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:58:50.89706664Z 53 PC: 18631 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:58:50.902859799Z 48 PC: 186f3 | Get DOS version
2018-12-17T22:58:50.904679138Z 74 PC: 16585 | Reallocate memory
2018-12-17T22:58:50.907090109Z 74 PC: 16585 | Reallocate memory
2018-12-17T22:58:50.909862069Z 68 PC: 17aa0 | I/O control for devices (Set for = '01')
2018-12-17T22:58:50.911274384Z 68 PC: 17aa0 | I/O control for devices (Set for = '')
2018-12-17T22:58:50.912822183Z 51 PC: 17abe | Get or set Ctrl-Break
2018-12-17T22:58:50.914475761Z 51 PC: 17aca | Get or set Ctrl-Break
2018-12-17T22:58:50.915685394Z 72 PC: 1482e | Allocate memory
2018-12-17T22:58:50.918722482Z 74 PC: 16585 | Reallocate memory
2018-12-17T22:58:50.921146208Z 72 PC: 1482e | Allocate memory
2018-12-17T22:58:50.922976578Z 37 PC: 15755 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:50.926227247Z 73 PC: 1482e | Release memory
2018-12-17T22:58:50.929675939Z 74 PC: 16585 | Reallocate memory
2018-12-17T22:58:50.931319829Z 51 PC: 17ad5 | Get or set Ctrl-Break
2018-12-17T22:58:50.932151002Z 37 PC: 17d57 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:50.934395771Z 37 PC: 17d61 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:50.93560304Z 37 PC: 17d6b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:50.936674825Z 53 PC: 15fb2 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:50.942073471Z 53 PC: 15fbf | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:58:50.943393392Z 53 PC: 15fcc | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:50.945414681Z 37 PC: 15fe7 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:58:50.948071715Z 53 PC: 15fef | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:50.950161803Z 37 PC: 15ffc | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:50.951943963Z 53 PC: 16003 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:58:50.954090627Z 37 PC: 16010 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:50.95633738Z 37 PC: 1601a | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:50.957981781Z 37 PC: 16025 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:58:50.959818313Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:50.96174284Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:50.963423388Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:50.965273986Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:50.967434086Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:50.968722117Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:50.970230472Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:50.97168188Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:50.973351177Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:50.977134278Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:50.979064005Z 37 PC: 1b841 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:50.980837439Z 37 PC: 1dad6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:58:50.982789979Z 37 PC: 1ae0c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:50.98824455Z 41 PC: 1aaef | Parse filename
2018-12-17T22:58:50.99050014Z 41 PC: 1aaf1 | Parse filename
2018-12-17T22:58:50.992185537Z 41 PC: 1aaf6 | Parse filename
2018-12-17T22:58:50.994187209Z 75 PC: 1ab0c | Execute program
2018-12-17T22:58:51.026276681Z 80 PC: 20f99 | Set current PSP
2018-12-17T22:58:51.02739885Z 48 PC: 20f9e | Get DOS version
2018-12-17T22:58:51.030899961Z 99 PC: 27780 | Get DBCS lead byte table pointer
2018-12-17T22:58:51.033956847Z 101 PC: 21024 | Get extended country info
2018-12-17T22:58:51.035374972Z 99 PC: 2102a | Get DBCS lead byte table pointer
2018-12-17T22:58:51.037588052Z 74 PC: 2108c | Reallocate memory
2018-12-17T22:58:51.039434743Z 25 PC: 210c3 | Get default drive
2018-12-17T22:58:51.040897171Z 37 PC: 20b83 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:58:51.04354091Z 37 PC: 20b8a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:51.045074713Z 37 PC: 20b91 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:51.049769497Z 74 PC: 1fd2c | Reallocate memory
2018-12-17T22:58:51.052647236Z 72 PC: 1fd6d | Allocate memory
2018-12-17T22:58:51.054729629Z 72 PC: 1fda5 | Allocate memory
2018-12-17T22:58:51.056860023Z 72 PC: 1fdad | Allocate memory