Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Yes.4864

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:48.140072859Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:48.142885618Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:48.144261872Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:48.145724326Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:48.147741384Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:48.149230009Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:48.150644688Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:48.153001889Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:48.154541441Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:48.155949275Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:48.157373033Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:48.161116063Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:48.162512478Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:48.163881941Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:48.166806696Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:48.169253671Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:48.171354718Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:48.173363532Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:48.175353071Z 53 PC: 12ffa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:48.181584386Z 37 PC: 1300f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:48.184006276Z 37 PC: 13017 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:48.185328291Z 37 PC: 1301f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:48.186721531Z 37 PC: 13027 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:48.188727967Z 68 PC: 13ae3 | I/O control for devices (Set for = '')
2018-12-17T21:51:48.191013063Z 26 PC: 12f45 | Set disk transfer address
2018-12-17T21:51:48.192095724Z 78 PC: 12f51 | Find first file
2018-12-17T21:51:48.198855861Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.210823518Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.217921653Z 61 PC: 136c0 | Open file (Filename = '\TEST.EXE')
2018-12-17T21:51:48.224863444Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:51:48.228660459Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T21:51:48.231460443Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.23349029Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.236216315Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.237454574Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.240289267Z 26 PC: 12f45 | Set disk transfer address
2018-12-17T21:51:48.242019345Z 78 PC: 12f51 | Find first file
2018-12-17T21:51:48.248030526Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.249292049Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.260417901Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.261640308Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.264604844Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.266416411Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.269286051Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.271110214Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.27868582Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.286803292Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.289870813Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.29197327Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.294962795Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.296391869Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.30000706Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.301439837Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.304356483Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.308922468Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.311861391Z 26 PC: 12f45 | Set disk transfer address
2018-12-17T21:51:48.312988978Z 78 PC: 12f51 | Find first file
2018-12-17T21:51:48.320263819Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.321710906Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.328462448Z 61 PC: 136c0 | Open file (Filename = '\SLEEP.COM')
2018-12-17T21:51:48.336128735Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:51:48.339057591Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T21:51:48.346098068Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.349430334Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.352851416Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.354599026Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.36264682Z 61 PC: 136c0 | Open file (Filename = '\SLEEP.COM')
2018-12-17T21:51:48.369637699Z 63 PC: 13793 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T21:51:48.377260549Z 64 PC: 13793 | Write file or device (Write 5000 bytes on handle 6)
2018-12-17T21:51:48.391083628Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.393771065Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.402228694Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.403917656Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.407584527Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.409081345Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.416184166Z 61 PC: 136c0 | Open file (Filename = '\PRINT.COM')
2018-12-17T21:51:48.427077361Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:51:48.429818858Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T21:51:48.440369902Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.445745594Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.448153535Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.449840334Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.457316605Z 61 PC: 136c0 | Open file (Filename = '\PRINT.COM')
2018-12-17T21:51:48.463737081Z 63 PC: 13793 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T21:51:48.471011951Z 64 PC: 13793 | Write file or device (Write 5000 bytes on handle 6)
2018-12-17T21:51:48.480435804Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.483278603Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.491551725Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.493797383Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.497917069Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.499493161Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.507203831Z 61 PC: 136c0 | Open file (Filename = '\HELLO.COM')
2018-12-17T21:51:48.514702241Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:51:48.518311237Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T21:51:48.527302959Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.529815815Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.532430279Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.535371864Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.543192177Z 61 PC: 136c0 | Open file (Filename = '\HELLO.COM')
2018-12-17T21:51:48.55017287Z 63 PC: 13793 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T21:51:48.558750351Z 64 PC: 13793 | Write file or device (Write 5000 bytes on handle 6)
2018-12-17T21:51:48.568802364Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.571296602Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.580307096Z 26 PC: 12f69 | Set disk transfer address
2018-12-17T21:51:48.581658523Z 79 PC: 12f6e | Find next file
2018-12-17T21:51:48.585023338Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.587738881Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.594448255Z 61 PC: 136c0 | Open file (Filename = '\PHANG.COM')
2018-12-17T21:51:48.602665713Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 5)
2018-12-17T21:51:48.608991494Z 63 PC: 13793 | Read file or device (Read 25 bytes on handle 6)
2018-12-17T21:51:48.615730444Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.618780395Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.621370729Z 48 PC: 1380e | Get DOS version
2018-12-17T21:51:48.623710268Z 61 PC: 136c0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.63068809Z 61 PC: 136c0 | Open file (Filename = '\PHANG.COM')
2018-12-17T21:51:48.637409504Z 63 PC: 13793 | Read file or device (Read 5488 bytes on handle 5)
2018-12-17T21:51:48.646185692Z 64 PC: 13793 | Write file or device (Write 5000 bytes on handle 6)
2018-12-17T21:51:48.655474746Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.657738229Z 62 PC: 13710 | Close file
2018-12-17T21:51:48.66609335Z 64 PC: 13418 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T21:51:48.670889928Z 64 PC: 13418 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:51:48.672596836Z 37 PC: 13151 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:48.674413163Z 37 PC: 13151 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:48.675413219Z 37 PC: 13151 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:48.676397903Z 37 PC: 13151 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:48.67825762Z 37 PC: 13151 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:48.679269922Z 37 PC: 13151 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:48.680270361Z 37 PC: 13151 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:48.681914634Z 37 PC: 13151 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:48.68294037Z 37 PC: 13151 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:48.683932671Z 37 PC: 13151 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:48.685969794Z 37 PC: 13151 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:48.686949366Z 37 PC: 13151 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:48.687931463Z 37 PC: 13151 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:48.689831301Z 37 PC: 13151 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:48.691497474Z 37 PC: 13151 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:48.692490459Z 37 PC: 13151 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:48.694687926Z 37 PC: 13151 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:48.695702771Z 37 PC: 13151 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:48.69731074Z 37 PC: 13151 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:48.699297414Z 76 PC: 13190 | Terminate with return code (Return code = '0')