Sample viewer

vx.netlux.org/Virus.DOS.HLLO.TPPE.13744

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:06:16.534591045Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:06:16.536524339Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:06:16.537685269Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:06:16.538768929Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:06:16.540551183Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:16.541649511Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:16.542706263Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:06:16.544351541Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:06:16.546137055Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:06:16.547676767Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:06:16.549731654Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:06:16.550855616Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:06:16.552041462Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:06:16.553588523Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:06:16.554685351Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:06:16.555704648Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:06:16.556920958Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:06:16.558157193Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:06:16.559648943Z 53 PC: 13eaa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:06:16.560656003Z 37 PC: 13ebf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:06:16.561871917Z 37 PC: 13ec7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:16.562803283Z 37 PC: 13ecf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:16.56372337Z 37 PC: 13ed7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:06:16.565917243Z 68 PC: 14c42 | I/O control for devices (Set for = '')
2018-12-17T22:06:16.567914663Z 64 PC: 142c8 | Write file or device (Write 46 bytes on handle 1)
2018-12-17T22:06:16.572908121Z 64 PC: 142c8 | Write file or device (Write 49 bytes on handle 1)
2018-12-17T22:06:16.603822586Z 60 PC: 14c26 | Create or truncate file
2018-12-17T22:06:16.872817625Z 68 PC: 14c42 | I/O control for devices (Set for = '')
2018-12-17T22:06:16.875244601Z 64 PC: 142a3 | Write file or device (Write 26 bytes on handle 5)
2018-12-17T22:06:16.879786868Z 62 PC: 142e2 | Close file
2018-12-17T22:06:16.888565649Z 41 PC: 13e0b | Parse filename
2018-12-17T22:06:16.890078919Z 41 PC: 13e19 | Parse filename
2018-12-17T22:06:16.892506986Z 75 PC: 13e24 | Execute program
2018-12-17T22:06:16.913801103Z 80 PC: 1d239 | Set current PSP
2018-12-17T22:06:16.914660306Z 48 PC: 1d23e | Get DOS version
2018-12-17T22:06:16.922736868Z 99 PC: 23a20 | Get DBCS lead byte table pointer
2018-12-17T22:06:16.927473922Z 101 PC: 1d2c4 | Get extended country info
2018-12-17T22:06:16.928853832Z 99 PC: 1d2ca | Get DBCS lead byte table pointer
2018-12-17T22:06:16.931394069Z 74 PC: 1d32c | Reallocate memory
2018-12-17T22:06:16.932704515Z 25 PC: 1d363 | Get default drive
2018-12-17T22:06:16.93379825Z 37 PC: 1ce23 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:06:16.935248552Z 37 PC: 1ce2a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:16.936327801Z 37 PC: 1ce31 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:16.940563055Z 74 PC: 1bfcc | Reallocate memory
2018-12-17T22:06:16.942159438Z 72 PC: 1c00d | Allocate memory
2018-12-17T22:06:16.943357483Z 72 PC: 1c045 | Allocate memory
2018-12-17T22:06:16.94460901Z 72 PC: 1c04d | Allocate memory