Sample viewer

vx.netlux.org/Virus.DOS.Hallochen.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:11:53.768798509Z 48 PC: 13150 | Get DOS version
2018-12-17T22:11:53.770511285Z 82 PC: 1312d | Get DOS internal pointers (SYSVARS)
2018-12-17T22:11:53.771778676Z 98 PC: 13213 | Get current PSP
2018-12-17T22:11:53.772721735Z 53 PC: 9f855 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:11:53.774562023Z 53 PC: 9f86a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:11:53.776181714Z 9 PC: 12b00 | Display string (Could not find end pointer)
2018-12-17T22:11:53.781886244Z 76 PC: 12c0a | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2443,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:51.273007528Z 48 PC: 13150 | Get DOS version
2018-12-25T11:45:51.274435602Z 82 PC: 1312d | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:51.275590271Z 98 PC: 13213 | Get current PSP
2018-12-25T11:45:51.276410312Z 53 PC: 9f855 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T11:45:51.277834074Z 53 PC: 9f86a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:51.279151638Z 9 PC: 12b00 | Display string (Could not find end pointer)
2018-12-25T11:45:51.284631937Z 76 PC: 12c0a | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2443,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:51.22157339Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:45:51.232480132Z 41 PC: 94fae | Parse filename
2018-12-25T11:45:51.244709899Z 41 PC: 9502f | Parse filename
2018-12-25T11:45:51.246428685Z 41 PC: 9504c | Parse filename
2018-12-25T11:45:51.248519623Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T11:45:51.250624663Z 71 PC: 986f3 | Get current directory
2018-12-25T11:45:51.253229444Z 78 PC: 986fe | Find first file
2018-12-25T11:45:51.261940525Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:45:51.266397827Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:45:51.27569316Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T11:45:51.28014896Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:45:51.281657186Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:45:51.282678893Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:45:51.283666899Z 62 PC: 122ab | Close file
2018-12-25T11:45:51.285298428Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.286931606Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.288215831Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.289517471Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.290973149Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.292835542Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.294159885Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.303644015Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.304997876Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.306300535Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.308167074Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.309512262Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.310835441Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.312873193Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:51.314536575Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T11:45:51.315699533Z 56 PC: 94df9 | Get or set country info
2018-12-25T11:45:51.318578027Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:45:51.324887658Z 25 PC: 94e62 | Get default drive
2018-12-25T11:45:51.326380948Z 71 PC: 970dd | Get current directory
2018-12-25T11:45:51.330580358Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:45:51.333620523Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T11:45:51.33573929Z 93 PC: 94f20 | File sharing functions
2018-12-25T11:45:51.338653721Z 93 PC: 94f27 | File sharing functions
2018-12-25T11:45:51.340387242Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T11:46:06.268535511Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:46:07.622590606Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:46:07.72451122Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:46:07.731163752Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T11:46:07.732912668Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T11:46:07.734788763Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T11:46:07.737388276Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T11:46:07.74028482Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:46:07.75273766Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:46:07.762318734Z 71 PC: 9856c | Get current directory
2018-12-25T11:46:07.765358637Z 73 PC: 97c09 | Release memory
2018-12-25T11:46:07.766608507Z 75 PC: 11821 | Execute program
2018-12-25T11:46:07.780155943Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T11:46:07.783992828Z 76 PC: 12a4b | Terminate with return code (Return code = '36')