Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Twog.3968

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:31.746547335Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:31.748224261Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:31.749364125Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:31.750658426Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:31.763600163Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:31.764979598Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:31.766381333Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:31.768304075Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:31.769716244Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:31.77110545Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:31.772667646Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:31.774670057Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:31.776066964Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:31.777467485Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:31.780047091Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:31.781357379Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:31.782636467Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:31.784632353Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:31.78584238Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:31.787219352Z 37 PC: 12d9f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:31.789341775Z 37 PC: 12da7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:31.801913506Z 37 PC: 12daf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:31.803221547Z 37 PC: 12db7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:31.805453489Z 68 PC: 13818 | I/O control for devices (Set for = '')
2018-12-17T23:11:31.807507824Z 64 PC: 1314d | Write file or device (Write 13 bytes on handle 1)
2018-12-17T23:11:31.812145382Z 48 PC: 13543 | Get DOS version
2018-12-17T23:11:31.814680355Z 61 PC: 133f5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:11:31.82223379Z 63 PC: 134c8 | Read file or device (Read 3968 bytes on handle 5)
2018-12-17T23:11:31.830024155Z 26 PC: 12cd7 | Set disk transfer address
2018-12-17T23:11:31.836588279Z 78 PC: 12ce3 | Find first file
2018-12-17T23:11:31.847003317Z 26 PC: 12cfb | Set disk transfer address
2018-12-17T23:11:31.848303658Z 79 PC: 12d00 | Find next file
2018-12-17T23:11:31.851228908Z 64 PC: 1314d | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:11:31.853591651Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:31.854810947Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:31.856102927Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:31.857381119Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:31.858487658Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:31.859537822Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:31.861008527Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:31.862292712Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:31.863548186Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:31.865508014Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:31.866813168Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:31.868104558Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:31.874220718Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:31.875557359Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:31.87685523Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:31.878705013Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:31.879967645Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:31.881249605Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:31.883185196Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:31.884486969Z 76 PC: 12f20 | Terminate with return code (Return code = '0')