Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Anti-NATO.4496

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:43.662296751Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:43.664469893Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:23:43.674457327Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:23:43.675807126Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:23:43.678231736Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:23:43.680231666Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:23:43.681869779Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:23:43.684138112Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:23:43.699153016Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:23:43.700487205Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:23:43.701816707Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:23:43.703784291Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:23:43.705506821Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:23:43.707218448Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:23:43.709464167Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:23:43.71121284Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:23:43.712908706Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:23:43.714956048Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:23:43.716362505Z 53 PC: 12f0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:23:43.717793031Z 37 PC: 12f1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:43.719726573Z 37 PC: 12f27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:23:43.721236861Z 37 PC: 12f2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:23:43.723166639Z 37 PC: 12f37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:23:43.725997042Z 68 PC: 13931 | I/O control for devices (Set for = '>v')
2018-12-17T22:23:43.727997385Z 26 PC: 12d15 | Set disk transfer address
2018-12-17T22:23:43.729876064Z 78 PC: 12d21 | Find first file
2018-12-17T22:23:43.748357243Z 26 PC: 12d15 | Set disk transfer address
2018-12-17T22:23:43.749824401Z 78 PC: 12d21 | Find first file
2018-12-17T22:23:43.756514147Z 48 PC: 1365c | Get DOS version
2018-12-17T22:23:43.75894048Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:43.761500477Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:43.763171551Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:23:43.764867881Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:23:43.782793889Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:23:43.784192649Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:23:43.785521498Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:23:43.788059198Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:23:43.789714273Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:23:43.791402156Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:23:43.793941777Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:23:43.806593701Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:23:43.807976352Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:23:43.809902149Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:23:43.811297314Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:23:43.812643724Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:23:43.814105893Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:23:43.815665011Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:23:43.816950386Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:23:43.818263069Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:23:43.819824866Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:23:43.821379652Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:23:43.822878454Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:23:43.825000627Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:23:43.826517851Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:23:43.828041215Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:23:43.829841645Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:23:43.846482648Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:23:43.848344492Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:23:43.850045645Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:23:43.851263976Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:23:43.852486001Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:23:43.854291948Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:23:43.856033658Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:23:43.857176338Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:23:43.859216942Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:23:43.860541085Z 53 PC: 12e84 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:23:43.86199297Z 37 PC: 12e8d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:23:43.864280879Z 48 PC: 1365c | Get DOS version
2018-12-17T22:23:43.866096206Z 41 PC: 12e3b | Parse filename
2018-12-17T22:23:43.868146899Z 41 PC: 12e49 | Parse filename
2018-12-17T22:23:43.879789621Z 75 PC: 12e54 | Execute program
2018-12-17T22:23:43.899260009Z 80 PC: 16959 | Set current PSP
2018-12-17T22:23:43.900435958Z 48 PC: 1695e | Get DOS version
2018-12-17T22:23:43.903035286Z 99 PC: 1d140 | Get DBCS lead byte table pointer
2018-12-17T22:23:43.906377531Z 101 PC: 169e4 | Get extended country info
2018-12-17T22:23:43.908079582Z 99 PC: 169ea | Get DBCS lead byte table pointer
2018-12-17T22:23:43.90967472Z 74 PC: 16a4c | Reallocate memory
2018-12-17T22:23:43.911929006Z 25 PC: 16a83 | Get default drive
2018-12-17T22:23:43.913441067Z 37 PC: 16543 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:23:43.9157728Z 37 PC: 1654a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:23:43.917754913Z 37 PC: 16551 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:23:43.922623168Z 74 PC: 156ec | Reallocate memory
2018-12-17T22:23:43.92441583Z 72 PC: 1572d | Allocate memory
2018-12-17T22:23:43.927400818Z 72 PC: 15765 | Allocate memory
2018-12-17T22:23:43.929499814Z 72 PC: 1576d | Allocate memory