Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Julius.40932

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:08:33.504394583Z 48 PC: 18aec | Get DOS version
2018-12-17T22:08:33.507051321Z 74 PC: 18b3c | Reallocate memory
2018-12-17T22:08:33.508827518Z 48 PC: 18ba0 | Get DOS version
2018-12-17T22:08:33.509901689Z 53 PC: 18ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:33.512042791Z 37 PC: 18bba | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:33.513475335Z 53 PC: 1b802 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:08:33.514579537Z 37 PC: 1b812 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:08:33.51627734Z 53 PC: 1b817 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:33.517622609Z 37 PC: 1b827 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:33.518744378Z 53 PC: 19556 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:08:33.520613115Z 53 PC: 19556 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:08:33.521734327Z 53 PC: 19556 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:08:33.522828127Z 53 PC: 19556 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:08:33.524550093Z 53 PC: 19556 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:08:33.525931887Z 53 PC: 19556 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:08:33.527270114Z 53 PC: 19556 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:08:33.532756872Z 53 PC: 19556 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:08:33.533976031Z 53 PC: 19556 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:08:33.535164649Z 53 PC: 19556 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:08:33.536850445Z 53 PC: 19556 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:08:33.538055781Z 37 PC: 19585 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:08:33.539042714Z 37 PC: 19585 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:08:33.54192721Z 37 PC: 19585 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:08:33.543102407Z 37 PC: 19585 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:08:33.544216881Z 37 PC: 19585 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:08:33.545875293Z 37 PC: 19585 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:08:33.547002879Z 37 PC: 19585 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:08:33.547979068Z 37 PC: 19585 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:08:33.549454312Z 37 PC: 1958c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:08:33.550458246Z 37 PC: 19591 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:08:33.551865776Z 68 PC: 18c4b | I/O control for devices (Set for = '%u3ۀ>t>tC>t>tCdr>uXuSEp=')
2018-12-17T22:08:33.554278536Z 68 PC: 18c4b | I/O control for devices (Set for = '1R1R1R1R1(')
2018-12-17T22:08:33.555533169Z 68 PC: 18c4b | I/O control for devices (Set for = ' u뿃')
2018-12-17T22:08:33.556717786Z 68 PC: 18c4b | I/O control for devices (Set for = '@H yu3')
2018-12-17T22:08:33.558213475Z 68 PC: 18c4b | I/O control for devices (Set for = '@H yu3')
2018-12-17T22:08:33.559942689Z 53 PC: 1633e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:33.560991328Z 53 PC: 1634b | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:08:33.562683468Z 53 PC: 16358 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:33.563972294Z 37 PC: 1636d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:33.565243764Z 37 PC: 16375 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:08:33.570841668Z 37 PC: 1637d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:33.572161194Z 53 PC: 16dfc | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:08:33.573315139Z 53 PC: 16e09 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:08:33.575969083Z 53 PC: 16e18 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:08:33.576995348Z 37 PC: 16e25 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:08:33.5779371Z 53 PC: 16e2c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:08:33.579478872Z 37 PC: 16e39 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:08:33.580594882Z 53 PC: 16e45 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:08:33.584529949Z 48 PC: 16f07 | Get DOS version
2018-12-17T22:08:33.586170902Z 74 PC: 15009 | Reallocate memory
2018-12-17T22:08:33.58775253Z 74 PC: 15009 | Reallocate memory
2018-12-17T22:08:33.589060672Z 68 PC: 162b4 | I/O control for devices (Set for = 'Windows')
2018-12-17T22:08:33.590725556Z 68 PC: 162b4 | I/O control for devices (Set for = '')
2018-12-17T22:08:33.592718048Z 51 PC: 162d2 | Get or set Ctrl-Break
2018-12-17T22:08:33.593474121Z 51 PC: 162de | Get or set Ctrl-Break
2018-12-17T22:08:33.597314881Z 74 PC: 15009 | Reallocate memory
2018-12-17T22:08:33.598987395Z 51 PC: 162e9 | Get or set Ctrl-Break
2018-12-17T22:08:33.600066915Z 37 PC: 1656b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:33.601595215Z 37 PC: 16575 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:08:33.603264879Z 37 PC: 1657f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:33.60426094Z 53 PC: 14a36 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:08:33.605233651Z 53 PC: 14a43 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:08:33.606966397Z 53 PC: 14a50 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:08:33.608157317Z 37 PC: 14a6b | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:08:33.609338464Z 53 PC: 14a73 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:08:33.613789005Z 37 PC: 14a80 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:08:33.614814924Z 53 PC: 14a87 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:08:33.615845515Z 37 PC: 14a94 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:08:33.621484218Z 37 PC: 14a9e | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:08:33.622713106Z 37 PC: 14aa9 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:08:33.623875565Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:08:33.62548126Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:08:33.626293059Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:08:33.627078093Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:08:33.629356464Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:08:33.630531973Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:08:33.631505941Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:08:33.632724189Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:08:33.63366468Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:08:33.634919894Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:08:33.636424942Z 37 PC: 195a1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:08:33.637359086Z 37 PC: 1b836 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:08:33.638433729Z 37 PC: 18cfc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:08:33.641411801Z 41 PC: 188d7 | Parse filename
2018-12-17T22:08:33.642544558Z 41 PC: 188d9 | Parse filename
2018-12-17T22:08:33.643915586Z 41 PC: 188de | Parse filename
2018-12-17T22:08:33.645638956Z 75 PC: 188f4 | Execute program
2018-12-17T22:08:33.666856264Z 80 PC: 1e9a9 | Set current PSP
2018-12-17T22:08:33.670059094Z 48 PC: 1e9ae | Get DOS version
2018-12-17T22:08:33.672090964Z 99 PC: 25190 | Get DBCS lead byte table pointer
2018-12-17T22:08:33.673921782Z 101 PC: 1ea34 | Get extended country info
2018-12-17T22:08:33.675065285Z 99 PC: 1ea3a | Get DBCS lead byte table pointer
2018-12-17T22:08:33.676553101Z 74 PC: 1ea9c | Reallocate memory
2018-12-17T22:08:33.677736058Z 25 PC: 1ead3 | Get default drive
2018-12-17T22:08:33.678575034Z 37 PC: 1e593 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:08:33.680081321Z 37 PC: 1e59a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:33.681169598Z 37 PC: 1e5a1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:33.68522203Z 74 PC: 1d73c | Reallocate memory
2018-12-17T22:08:33.696592987Z 72 PC: 1d77d | Allocate memory
2018-12-17T22:08:33.698882305Z 72 PC: 1d7b5 | Allocate memory
2018-12-17T22:08:33.700475824Z 72 PC: 1d7bd | Allocate memory