Sample viewer

vx.netlux.org/Virus.DOS.Hallochen.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:04.663844404Z 48 PC: 130f0 | Get DOS version
2018-12-17T23:06:04.665609433Z 82 PC: 130cd | Get DOS internal pointers (SYSVARS)
2018-12-17T23:06:04.667520636Z 98 PC: 131b3 | Get current PSP
2018-12-17T23:06:04.668753174Z 53 PC: 9f855 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:06:04.670249958Z 53 PC: 9f86a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:04.684393901Z 9 PC: 12c22 | Display string (Could not find end pointer)
2018-12-17T23:06:04.690059023Z 76 PC: 12c28 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15416,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:43:20.660595268Z 48 PC: 130f0 | Get DOS version
2018-12-25T12:43:20.662758429Z 82 PC: 130cd | Get DOS internal pointers (SYSVARS)
2018-12-25T12:43:20.665443421Z 98 PC: 131b3 | Get current PSP
2018-12-25T12:43:20.666892663Z 53 PC: 9f855 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:43:20.668576059Z 53 PC: 9f86a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:43:20.671774573Z 9 PC: 12c22 | Display string (Could not find end pointer)
2018-12-25T12:43:20.678490536Z 76 PC: 12c28 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15416,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:43:21.299603071Z 48 PC: 130f0 | Get DOS version
2018-12-25T12:43:21.300905932Z 82 PC: 130cd | Get DOS internal pointers (SYSVARS)
2018-12-25T12:43:21.302630654Z 98 PC: 131b3 | Get current PSP
2018-12-25T12:43:21.303541506Z 53 PC: 9f855 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:43:21.304589729Z 53 PC: 9f86a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:43:21.307275308Z 9 PC: 12c22 | Display string (Could not find end pointer)
2018-12-25T12:43:21.311041231Z 76 PC: 12c28 | Terminate with return code (Return code = '0')