Sample viewer

vx.netlux.org/Virus.DOS.HLLO.FU.8608

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:11:01.845445921Z 53 PC: 139ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:11:01.853417905Z 53 PC: 139ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:11:01.854476754Z 53 PC: 139ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:11:01.855492167Z 53 PC: 139ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:11:01.85700999Z 53 PC: 139ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:11:01.85794406Z 53 PC: 139ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:11:01.859250096Z 53 PC: 139ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:11:01.861008771Z 53 PC: 139ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:11:01.862928566Z 53 PC: 139ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:11:01.86439247Z 53 PC: 139ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:11:01.866276763Z 53 PC: 139ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:11:01.867442708Z 53 PC: 139ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:11:01.86869991Z 53 PC: 139ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:11:01.870187986Z 53 PC: 139ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:11:01.87432428Z 53 PC: 139ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:11:01.875468508Z 53 PC: 139ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:11:01.876777395Z 53 PC: 139ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:11:01.878421156Z 53 PC: 139ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:11:01.879458396Z 53 PC: 139ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:11:01.88056995Z 37 PC: 139ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:11:01.882765698Z 37 PC: 13a07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:11:01.883766884Z 37 PC: 13a0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:11:01.884779403Z 37 PC: 13a17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:11:01.887054733Z 68 PC: 14821 | I/O control for devices (Set for = '')
2018-12-17T22:11:01.996130395Z 37 PC: 130b1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:11:01.997531951Z 44 PC: 14958 | Get time 0x14958: mov word ptr [0x3e], cx
0x1495c: mov word ptr [0x40], dx
0x14960: retf
0x14961: mov bx, sp
0x14963: mov dx, ds
0x14965: lds si, ptr ss:[bx + 0xa]
0x14969: les di, ptr ss:[bx + 6]
0x1496d: mov cx, word ptr ss:[bx + 4]
0x14971: cld
0x14972: cmp si, di
0x14974: jae 0x1497d
0x14976: add si, cx
0x14978: add di, cx
0x1497a: dec si
0x1497b: dec di
0x1497c: std
0x1497d: rep movsb byte ptr es:[di], byte ptr [si]
0x1497f: cld
0x14980: mov ds, dx
0x14982: retf 0xa
2018-12-17T22:11:02.000709133Z 25 PC: 144ee | Get default drive
2018-12-17T22:11:02.001767414Z 71 PC: 14501 | Get current directory
2018-12-17T22:11:02.005212069Z 26 PC: 137f7 | Set disk transfer address
2018-12-17T22:11:02.00687907Z 78 PC: 13803 | Find first file
2018-12-17T22:11:02.010933143Z 26 PC: 1381b | Set disk transfer address
2018-12-17T22:11:02.011987278Z 79 PC: 13820 | Find next file
2018-12-17T22:11:02.014869084Z 48 PC: 14461 | Get DOS version
2018-12-17T22:11:02.016179375Z 61 PC: 14313 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:11:02.021683127Z 66 PC: 14445 | Move file pointer
2018-12-17T22:11:02.033063225Z 63 PC: 143e6 | Read file or device (Read 8608 bytes on handle 5)
2018-12-17T22:11:02.040160044Z 62 PC: 14363 | Close file