Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Rvrsi.4476

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:17:57.969824506Z 74 PC: 13f29 | Reallocate memory
2018-12-17T22:17:57.972499975Z 74 PC: 13f29 | Reallocate memory
2018-12-17T22:17:57.974636402Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:57.97650825Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:17:57.978677662Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:17:57.980146772Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:57.981461798Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:57.982618912Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:57.984493085Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:17:57.98588809Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:17:57.987073227Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:17:57.988700682Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:17:57.989854454Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:17:57.991175953Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:17:57.993452242Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:17:57.994652268Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:17:57.995686261Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:17:58.003335441Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:17:58.004459531Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:17:58.005839811Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:58.007808476Z 53 PC: 134b2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:17:58.008830864Z 37 PC: 134c7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:58.009838686Z 37 PC: 134cf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:58.01156939Z 37 PC: 134d7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:58.0126548Z 37 PC: 134df | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:58.013825008Z 68 PC: 1384f | I/O control for devices (Set for = '')
2018-12-17T22:17:58.063178715Z 37 PC: 12ed5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:17:58.064482318Z 26 PC: 12de5 | Set disk transfer address
2018-12-17T22:17:58.065322082Z 78 PC: 12df1 | Find first file
2018-12-17T22:17:58.077735662Z 60 PC: 13bc8 | Create or truncate file
2018-12-17T22:17:58.092424083Z 48 PC: 13d4d | Get DOS version
2018-12-17T22:17:58.093788141Z 61 PC: 13bc8 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:17:58.100441749Z 63 PC: 13c9b | Read file or device (Read 2048 bytes on handle 6)
2018-12-17T22:17:58.107365784Z 64 PC: 13c9b | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T22:17:58.114855188Z 63 PC: 13c9b | Read file or device (Read 2048 bytes on handle 6)
2018-12-17T22:17:58.120227337Z 64 PC: 13c9b | Write file or device (Write 2048 bytes on handle 5)
2018-12-17T22:17:58.126530725Z 63 PC: 13c9b | Read file or device (Read 2048 bytes on handle 6)
2018-12-17T22:17:58.129538754Z 64 PC: 13c9b | Write file or device (Write 380 bytes on handle 5)
2018-12-17T22:17:58.134012524Z 63 PC: 13c9b | Read file or device (Read 2048 bytes on handle 6)
2018-12-17T22:17:58.136000803Z 62 PC: 13c18 | Close file
2018-12-17T22:17:58.2890561Z 59 PC: 13ea1 | Change current directory
2018-12-17T22:17:58.292285743Z 26 PC: 12e09 | Set disk transfer address
2018-12-17T22:17:58.293343872Z 79 PC: 12e0e | Find next file
2018-12-17T22:17:58.295238889Z 60 PC: 13bc8 | Create or truncate file
2018-12-17T22:17:58.30390084Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:58.304847174Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:17:58.305610188Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:17:58.306670615Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:58.308088056Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:58.309178309Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:58.310048893Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:17:58.31129565Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:17:58.312123815Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:17:58.312848255Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:17:58.314002128Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:17:58.314663148Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:17:58.315279662Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:17:58.316650234Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:17:58.317463172Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:17:58.318181417Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:17:58.319309546Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:17:58.320097078Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:58.320831583Z 37 PC: 135c6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:17:58.321833549Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.323087045Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.324341029Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.325717624Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.326964275Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.328300847Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.329823532Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.33126707Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.332637752Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.334092731Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.335364585Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.336531845Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.338215525Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.339626215Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.341276492Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.342882359Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.344341343Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.345730124Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.347148783Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.348324564Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.349644166Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.351265346Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.352612807Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.354036515Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.355610009Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.356960225Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.358465042Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.360096708Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.361427406Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.362764729Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.364154895Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.365535844Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.3671266Z 6 PC: 1364d | Direct console I/O
2018-12-17T22:17:58.371023094Z 76 PC: 13605 | Terminate with return code (Return code = '3')