Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Tyst

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:30.533585806Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:30.539041715Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:30.541666414Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:30.543035752Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:30.544834016Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:30.547013864Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:30.548617932Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:30.55033007Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:30.553997967Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:30.555247801Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:30.556460726Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:30.558182594Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:30.559355788Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:30.560472907Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:30.562716009Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:30.564068055Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:30.565415927Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:30.567584166Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:30.569484202Z 53 PC: 12dc2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:30.571373047Z 37 PC: 12dd7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:30.573812173Z 37 PC: 12ddf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:30.574938472Z 37 PC: 12de7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:30.578057427Z 37 PC: 12def | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:30.58264929Z 68 PC: 1315f | I/O control for devices (Set for = '')
2018-12-17T23:09:30.584212791Z 26 PC: 12bd5 | Set disk transfer address
2018-12-17T23:09:30.585310844Z 78 PC: 12be1 | Find first file
2018-12-17T23:09:30.596305094Z 64 PC: 13262 | Write file or device (Write 31 bytes on handle 1)
2018-12-17T23:09:30.600672394Z 26 PC: 12bf9 | Set disk transfer address
2018-12-17T23:09:30.601431284Z 79 PC: 12bfe | Find next file
2018-12-17T23:09:30.605445169Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:30.607530217Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:30.608813247Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:30.610109394Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:30.612118143Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:30.613583863Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:30.615056944Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:30.618179042Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:30.619522669Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:30.621133045Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:30.624576717Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:30.625556428Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:30.62647193Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:30.641783913Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:30.643136231Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:30.64432418Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:30.646874402Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:30.647888122Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:30.648914837Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:30.651146245Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:30.652222014Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:30.653453371Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:30.655107981Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:30.656339174Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:30.657233703Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:30.658645899Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:30.659917342Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:30.661546477Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:30.663912189Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:30.665416316Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:30.668148597Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:30.670820036Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:30.672424536Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:30.673914438Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:30.67556919Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:30.676801319Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:30.678415731Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:30.681419254Z 37 PC: 12c45 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:30.683379439Z 48 PC: 13633 | Get DOS version
2018-12-17T23:09:30.685423958Z 41 PC: 12cc5 | Parse filename
2018-12-17T23:09:30.690877465Z 41 PC: 12cd3 | Parse filename
2018-12-17T23:09:30.692359752Z 75 PC: 12cde | Execute program
2018-12-17T23:09:30.71620549Z 80 PC: 19309 | Set current PSP
2018-12-17T23:09:30.718298668Z 48 PC: 1930e | Get DOS version
2018-12-17T23:09:30.719790858Z 99 PC: 1faf0 | Get DBCS lead byte table pointer
2018-12-17T23:09:30.72278491Z 101 PC: 19394 | Get extended country info
2018-12-17T23:09:30.728937723Z 99 PC: 1939a | Get DBCS lead byte table pointer
2018-12-17T23:09:30.73037125Z 74 PC: 193fc | Reallocate memory
2018-12-17T23:09:30.731742697Z 25 PC: 19433 | Get default drive
2018-12-17T23:09:30.733572664Z 37 PC: 18ef3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:09:30.735655942Z 37 PC: 18efa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:30.737161665Z 37 PC: 18f01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:30.74190431Z 74 PC: 1809c | Reallocate memory
2018-12-17T23:09:30.744346887Z 72 PC: 180dd | Allocate memory
2018-12-17T23:09:30.746337776Z 72 PC: 18115 | Allocate memory
2018-12-17T23:09:30.748409316Z 72 PC: 1811d | Allocate memory