Sample viewer

vx.netlux.org/Virus.DOS.HLLO.3968

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:16.912651241Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:16.917782933Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:16.920302958Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:02:16.922711824Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:16.924668611Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:16.931918493Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:16.934547112Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:16.936941441Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:16.941436627Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:16.944067901Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:16.946533634Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:16.949153467Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:16.95102868Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:16.952825516Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:16.964874084Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:16.966695827Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:16.968350096Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:02:16.970019733Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:02:16.973042833Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:02:16.987032168Z 37 PC: 12daf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:16.989397292Z 37 PC: 12db7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:17.00472394Z 37 PC: 12dbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:17.007292486Z 37 PC: 12dc7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:02:17.010141449Z 68 PC: 13828 | I/O control for devices (Set for = '')
2018-12-17T23:02:17.017498052Z 64 PC: 1315d | Write file or device (Write 13 bytes on handle 1)
2018-12-17T23:02:17.022842333Z 48 PC: 13553 | Get DOS version
2018-12-17T23:02:17.024928663Z 61 PC: 13405 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:02:17.033462388Z 63 PC: 134d8 | Read file or device (Read 3968 bytes on handle 5)
2018-12-17T23:02:17.04174503Z 26 PC: 12ce7 | Set disk transfer address
2018-12-17T23:02:17.043203009Z 78 PC: 12cf3 | Find first file
2018-12-17T23:02:17.05072369Z 26 PC: 12d0b | Set disk transfer address
2018-12-17T23:02:17.05220308Z 79 PC: 12d10 | Find next file
2018-12-17T23:02:17.05642386Z 64 PC: 1315d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:02:17.059365077Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:17.06481645Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:17.066582798Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:02:17.076936873Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:17.078695558Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:17.080190326Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:17.087410873Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:17.089903807Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:17.091724768Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:17.093514882Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:17.107302257Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:17.108941237Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:17.110223506Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:17.11243937Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:17.113667297Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:17.114889454Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:17.117183884Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:02:17.11879432Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:02:17.120368588Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:02:17.122871391Z 76 PC: 12f30 | Terminate with return code (Return code = '0')