Sample viewer

vx.netlux.org/Virus.DOS.HLLO.DPOG-based

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:00.104234648Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:00.106252853Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:00.108015485Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:00.109562233Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:00.112293193Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:00.113730814Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:00.115158359Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:00.129526461Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:00.130981903Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:00.132167881Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:00.133560656Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:00.135013329Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:00.136245542Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:00.137428543Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:00.139293668Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:00.140546677Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:00.141775861Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:00.143736331Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:00.144897188Z 53 PC: 12e9a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:00.146112015Z 37 PC: 12eaf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:00.14782791Z 37 PC: 12eb7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:00.149052402Z 37 PC: 12ebf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:00.150420846Z 37 PC: 12ec7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:00.153262162Z 68 PC: 13988 | I/O control for devices (Set for = '')
2018-12-17T23:04:00.155063625Z 48 PC: 136ae | Get DOS version
2018-12-17T23:04:00.156598575Z 61 PC: 13560 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:04:00.166336575Z 63 PC: 13633 | Read file or device (Read 4464 bytes on handle 5)
2018-12-17T23:04:00.177654908Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.179597345Z 26 PC: 12de5 | Set disk transfer address
2018-12-17T23:04:00.181939593Z 78 PC: 12df1 | Find first file
2018-12-17T23:04:00.192141384Z 61 PC: 13560 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:04:00.198723516Z 66 PC: 13692 | Move file pointer
2018-12-17T23:04:00.201020756Z 63 PC: 13633 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:04:00.204067249Z 63 PC: 13633 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:04:00.206913252Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.210897114Z 61 PC: 13560 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:04:00.217794435Z 64 PC: 13633 | Write file or device (Write 4464 bytes on handle 5)
2018-12-17T23:04:00.23165391Z 66 PC: 13692 | Move file pointer
2018-12-17T23:04:00.233751565Z 64 PC: 13633 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:04:00.241076791Z 64 PC: 13633 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:04:00.243828641Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.252013142Z 26 PC: 12e09 | Set disk transfer address
2018-12-17T23:04:00.253484438Z 79 PC: 12e0e | Find next file
2018-12-17T23:04:00.255855094Z 26 PC: 12de5 | Set disk transfer address
2018-12-17T23:04:00.25712538Z 78 PC: 12df1 | Find first file
2018-12-17T23:04:00.264346457Z 61 PC: 13560 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:00.2711419Z 66 PC: 13692 | Move file pointer
2018-12-17T23:04:00.27319645Z 63 PC: 13633 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:04:00.280294319Z 63 PC: 13633 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:04:00.283014145Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.285269608Z 61 PC: 13560 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:00.293305124Z 64 PC: 13633 | Write file or device (Write 4464 bytes on handle 5)
2018-12-17T23:04:00.302296802Z 66 PC: 13692 | Move file pointer
2018-12-17T23:04:00.304101125Z 64 PC: 13633 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:04:00.312010419Z 64 PC: 13633 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:04:00.315080984Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.323147174Z 26 PC: 12e09 | Set disk transfer address
2018-12-17T23:04:00.325033231Z 79 PC: 12e0e | Find next file
2018-12-17T23:04:00.32818482Z 61 PC: 13560 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:00.335340454Z 66 PC: 13692 | Move file pointer
2018-12-17T23:04:00.33795148Z 63 PC: 13633 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:04:00.344301683Z 63 PC: 13633 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:04:00.346801992Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.349908029Z 61 PC: 13560 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:00.356717878Z 64 PC: 13633 | Write file or device (Write 4464 bytes on handle 5)
2018-12-17T23:04:00.365379512Z 66 PC: 13692 | Move file pointer
2018-12-17T23:04:00.368178697Z 64 PC: 13633 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:04:00.375000936Z 64 PC: 13633 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:04:00.378405738Z 62 PC: 135b0 | Close file
2018-12-17T23:04:00.387931137Z 26 PC: 12e09 | Set disk transfer address
2018-12-17T23:04:00.389370598Z 79 PC: 12e0e | Find next file
2018-12-17T23:04:00.392691828Z 64 PC: 132b8 | Write file or device (Write 25 bytes on handle 1)
2018-12-17T23:04:00.399307601Z 64 PC: 132b8 | Write file or device (Write 25 bytes on handle 1)
2018-12-17T23:04:00.404659546Z 64 PC: 132b8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:04:00.406708785Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:00.408951766Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:00.410735696Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:00.412179298Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:00.41434028Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:00.416076068Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:00.417570986Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:00.41971638Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:00.421465014Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:00.422882862Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:00.424497159Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:00.426685995Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:00.428097503Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:00.429512331Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:00.431856588Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:00.433247492Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:00.434675403Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:00.437037339Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:00.43846429Z 37 PC: 12ff1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:00.439866098Z 76 PC: 13030 | Terminate with return code (Return code = '0')