Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Gothmod.5071

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:32.465570429Z 53 PC: 1362a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:32.467520504Z 53 PC: 1362a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:32.469686218Z 53 PC: 1362a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:32.471429121Z 53 PC: 1362a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:32.473170836Z 53 PC: 1362a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:32.475535471Z 53 PC: 1362a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:32.477047993Z 53 PC: 1362a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:32.478682744Z 53 PC: 1362a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:32.481924476Z 53 PC: 1362a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:32.483768587Z 53 PC: 1362a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:32.485458396Z 53 PC: 1362a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:32.488522725Z 53 PC: 1362a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:32.490309618Z 53 PC: 1362a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:32.492127413Z 53 PC: 1362a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:32.493843753Z 53 PC: 1362a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:32.496623105Z 53 PC: 1362a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:32.498351618Z 53 PC: 1362a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:32.500057416Z 53 PC: 1362a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:32.503085599Z 53 PC: 1362a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:32.506739409Z 37 PC: 1363f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:32.508191761Z 37 PC: 13647 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:32.514831242Z 37 PC: 1364f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:32.516265261Z 37 PC: 13657 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:32.518500261Z 68 PC: 143b3 | I/O control for devices (Set for = '')
2018-12-17T23:01:32.523758528Z 44 PC: 144ea | Get time 0x144ea: mov word ptr [0x3e], cx
0x144ee: mov word ptr [0x40], dx
0x144f2: retf
0x144f3: call 0x1453a
0x144f6: jb 0x14507
0x144f8: mov cx, word ptr es:[di + 4]
0x144fc: cmp cx, 1
0x144ff: je 0x14507
0x14501: xor bx, bx
0x14503: push cs
0x14504: call 0x24067
0x14507: retf 4
0x1450a: call 0x1453a
0x1450d: jb 0x14522
0x1450f: mov ax, cx
0x14511: mov dx, bx
0x14513: mov cx, word ptr es:[di + 4]
0x14517: cmp cx, 1
0x1451a: je 0x14522
0x1451c: xor bx, bx
2018-12-17T23:01:32.526738956Z 25 PC: 13f5c | Get default drive
2018-12-17T23:01:32.529329548Z 71 PC: 13f6f | Get current directory
2018-12-17T23:01:32.539422758Z 26 PC: 1359c | Set disk transfer address
2018-12-17T23:01:32.543530447Z 78 PC: 1359c | Find first file
2018-12-17T23:01:32.551576138Z 48 PC: 13ecf | Get DOS version
2018-12-17T23:01:32.554434727Z 61 PC: 13d81 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:01:32.562602624Z 61 PC: 13d81 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:01:32.570298832Z 66 PC: 14554 | Move file pointer
2018-12-17T23:01:32.573305731Z 66 PC: 14562 | Move file pointer
2018-12-17T23:01:32.575093107Z 66 PC: 14570 | Move file pointer
2018-12-17T23:01:32.576840766Z 66 PC: 14554 | Move file pointer
2018-12-17T23:01:32.578578129Z 66 PC: 14562 | Move file pointer
2018-12-17T23:01:32.581183716Z 66 PC: 14570 | Move file pointer
2018-12-17T23:01:32.583008005Z 64 PC: 13db2 | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:01:32.599456333Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.604385451Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.609408813Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.61285264Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.617435772Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.627825075Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.632646386Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.637023547Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.641193022Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.650350105Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.655965859Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.659855053Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.66366831Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.672910059Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.678912119Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.682378102Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.686136908Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.697381497Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.702203174Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.705699316Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.709798075Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.723484168Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.72841859Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.732670368Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.736730031Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.746092773Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.751603998Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.755617154Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.760132845Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.768842956Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.774593234Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.778001298Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.781678616Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.791034355Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.795695362Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.799096165Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.803275193Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.811974861Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.816742771Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.820707699Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.825253367Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.834217728Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.839440055Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.842672025Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.846341308Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.855220336Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.860306954Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.863798637Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.867608356Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.877530919Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.882368437Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.885862621Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.890580009Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.900338628Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.905176667Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.909283121Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.91307341Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.916814955Z 64 PC: 13e54 | Write file or device (Write 256 bytes on handle 6)
2018-12-17T23:01:32.926500943Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.92975483Z 64 PC: 13e54 | Write file or device (Write 80 bytes on handle 6)
2018-12-17T23:01:32.933423129Z 63 PC: 13e54 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T23:01:32.936842966Z 62 PC: 13dd1 | Close file
2018-12-17T23:01:32.939454079Z 62 PC: 13dd1 | Close file
2018-12-17T23:01:32.94908476Z 64 PC: 13a48 | Write file or device (Write 35 bytes on handle 1)
2018-12-17T23:01:32.955160955Z 64 PC: 13a48 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:01:32.95818921Z 37 PC: 13781 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:32.959879863Z 37 PC: 13781 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:32.96236731Z 37 PC: 13781 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:32.964604747Z 37 PC: 13781 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:32.966295604Z 37 PC: 13781 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:32.967957216Z 37 PC: 13781 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:32.970484713Z 37 PC: 13781 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:32.972149473Z 37 PC: 13781 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:32.973803525Z 37 PC: 13781 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:32.976068875Z 37 PC: 13781 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:32.977755898Z 37 PC: 13781 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:32.979488065Z 37 PC: 13781 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:32.981984244Z 37 PC: 13781 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:32.983805591Z 37 PC: 13781 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:32.985459317Z 37 PC: 13781 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:32.987716106Z 37 PC: 13781 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:32.989387099Z 37 PC: 13781 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:32.991047688Z 37 PC: 13781 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:32.993309144Z 37 PC: 13781 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:32.995458096Z 76 PC: 137c0 | Terminate with return code (Return code = '0')