Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Pu

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:47.412074964Z 48 PC: 13268 | Get DOS version
2018-12-17T22:23:47.415138731Z 74 PC: 13268 | Reallocate memory
2018-12-17T22:23:47.417645334Z 37 PC: 13268 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:23:47.505535118Z 53 PC: 13268 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:47.507293961Z 37 PC: 13268 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:47.514291997Z 25 PC: 13268 | Get default drive
2018-12-17T22:23:47.515594Z 71 PC: 13268 | Get current directory
2018-12-17T22:23:47.519808016Z 26 PC: 1576b | Set disk transfer address
2018-12-17T22:23:47.522845334Z 78 PC: 1579d | Find first file
2018-12-17T22:23:47.528943036Z 61 PC: 13268 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:23:47.533793378Z 63 PC: 13268 | Read file or device (Read 256 bytes on handle 5)
2018-12-17T22:23:47.540849179Z 66 PC: 13268 | Move file pointer
2018-12-17T22:23:47.543357708Z 64 PC: 13268 | Write file or device (Write 12032 bytes on handle 5)
2018-12-17T22:23:47.559181638Z 62 PC: 13268 | Close file
2018-12-17T22:23:47.574007869Z 37 PC: 13268 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:23:47.575701544Z 76 PC: 13268 | Terminate with return code (Return code = '0')