Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Fobos.6608

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:09:51.231875319Z 53 PC: 131ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:09:51.234027281Z 53 PC: 131ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:09:51.235341648Z 53 PC: 131ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:09:51.236647562Z 53 PC: 131ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:09:51.238729324Z 53 PC: 131ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:09:51.240354662Z 53 PC: 131ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:09:51.241635832Z 53 PC: 131ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:09:51.244029696Z 53 PC: 131ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:09:51.245201753Z 53 PC: 131ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:09:51.246688465Z 53 PC: 131ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:09:51.248779737Z 53 PC: 131ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:09:51.249951243Z 53 PC: 131ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:09:51.251071Z 53 PC: 131ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:09:51.252363787Z 53 PC: 131ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:09:51.253712198Z 53 PC: 131ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:09:51.254829559Z 53 PC: 131ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:09:51.255925574Z 53 PC: 131ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:09:51.257637906Z 53 PC: 131ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:09:51.2588019Z 53 PC: 131ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:09:51.259972452Z 37 PC: 131df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:09:51.265133762Z 37 PC: 131e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:09:51.266444506Z 37 PC: 131ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:09:51.267721946Z 37 PC: 131f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:09:51.270024327Z 68 PC: 140da | I/O control for devices (Set for = '�G&�W3�5�;�=�Ìَ��.��tD���')
2018-12-17T22:09:51.272677696Z 60 PC: 140be | Create or truncate file
2018-12-17T22:09:51.289876369Z 68 PC: 140da | I/O control for devices (Set for = '�G&�W3�5�;�=�Ìَ��.��tD���')
2018-12-17T22:09:51.292446969Z 64 PC: 137cb | Write file or device (Write 86 bytes on handle 5)
2018-12-17T22:09:51.296995245Z 62 PC: 1380a | Close file
2018-12-17T22:09:51.305607919Z 48 PC: 13ceb | Get DOS version
2018-12-17T22:09:51.307629524Z 61 PC: 13b29 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:09:51.314732647Z 63 PC: 13bfc | Read file or device (Read 6608 bytes on handle 5)
2018-12-17T22:09:51.322441133Z 62 PC: 13b79 | Close file
2018-12-17T22:09:51.325603726Z 60 PC: 13b29 | Create or truncate file
2018-12-17T22:09:51.337292211Z 64 PC: 13bfc | Write file or device (Write 6608 bytes on handle 5)
2018-12-17T22:09:51.345864861Z 62 PC: 13b79 | Close file
2018-12-17T22:09:51.3553135Z 53 PC: 13144 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:09:51.356349545Z 37 PC: 1314d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:09:51.357517665Z 53 PC: 13144 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:09:51.359169035Z 37 PC: 1314d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:09:51.360329371Z 53 PC: 13144 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:09:51.361393826Z 37 PC: 1314d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:09:51.362694357Z 53 PC: 13144 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:09:51.364058446Z 37 PC: 1314d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:09:51.365024185Z 53 PC: 13144 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:09:51.366260238Z 37 PC: 1314d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:09:51.367555134Z 53 PC: 13144 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:09:51.368678962Z 37 PC: 1314d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:09:51.369856172Z 53 PC: 13144 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:09:51.371046461Z 37 PC: 1314d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:09:51.371920517Z 53 PC: 13144 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:09:51.373011187Z 37 PC: 1314d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:09:51.374134171Z 53 PC: 13144 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:09:51.375000249Z 37 PC: 1314d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:09:51.376335269Z 53 PC: 13144 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:09:51.377714022Z 37 PC: 1314d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:09:51.378492089Z 53 PC: 13144 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:09:51.379256569Z 37 PC: 1314d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:09:51.380549003Z 53 PC: 13144 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:09:51.381529964Z 37 PC: 1314d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:09:51.382413539Z 53 PC: 13144 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:09:51.384137469Z 37 PC: 1314d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:09:51.385205778Z 53 PC: 13144 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:09:51.386270168Z 37 PC: 1314d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:09:51.387794056Z 53 PC: 13144 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:09:51.388849273Z 37 PC: 1314d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:09:51.389754143Z 53 PC: 13144 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:09:51.391237927Z 37 PC: 1314d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:09:51.392424639Z 53 PC: 13144 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:09:51.393485275Z 37 PC: 1314d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:09:51.39642244Z 53 PC: 13144 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:09:51.397522025Z 37 PC: 1314d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:09:51.398963718Z 53 PC: 13144 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:09:51.400492194Z 37 PC: 1314d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:09:51.402155574Z 41 PC: 130fb | Parse filename
2018-12-17T22:09:51.403616226Z 41 PC: 13109 | Parse filename
2018-12-17T22:09:51.40606368Z 75 PC: 13114 | Execute program
2018-12-17T22:09:51.428416637Z 80 PC: 3bff9 | Set current PSP
2018-12-17T22:09:51.42985506Z 48 PC: 3bffe | Get DOS version
2018-12-17T22:09:51.433089353Z 99 PC: 427e0 | Get DBCS lead byte table pointer
2018-12-17T22:09:51.435878674Z 101 PC: 3c084 | Get extended country info
2018-12-17T22:09:51.437037969Z 99 PC: 3c08a | Get DBCS lead byte table pointer
2018-12-17T22:09:51.438881759Z 74 PC: 3c0ec | Reallocate memory
2018-12-17T22:09:51.440651824Z 25 PC: 3c123 | Get default drive
2018-12-17T22:09:51.442117807Z 37 PC: 3bbe3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:09:51.443610525Z 37 PC: 3bbea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:09:51.444637865Z 37 PC: 3bbf1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:09:51.449030632Z 74 PC: 3ad8c | Reallocate memory
2018-12-17T22:09:51.450731621Z 72 PC: 3adcd | Allocate memory
2018-12-17T22:09:51.452204799Z 72 PC: 3ae05 | Allocate memory
2018-12-17T22:09:51.453852665Z 72 PC: 3ae0d | Allocate memory