Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Nmkamil.8383.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:09.391147735Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:28:09.394068373Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:09.396210883Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:09.39796371Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:28:09.399946795Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:28:09.402459423Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:09.404288988Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:28:09.406960042Z 68 PC: 12fa1 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:28:09.410241479Z 68 PC: 12fa1 | I/O control for devices (Set for = '')
2018-12-17T22:28:09.41391631Z 67 PC: 143f3 | Get or set file attributes
2018-12-17T22:28:09.420590728Z 61 PC: 14d4d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:28:09.430694389Z 68 PC: 13c2a | I/O control for devices (Set for = '��')
2018-12-17T22:28:09.432903154Z 68 PC: 12fa1 | I/O control for devices (Set for = '')
2018-12-17T22:28:09.435876013Z 63 PC: 13120 | Read file or device (Read 8192 bytes on handle 5)
2018-12-17T22:28:09.445868295Z 63 PC: 13120 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:28:09.454531126Z 62 PC: 1442e | Close file
2018-12-17T22:28:09.459414281Z 64 PC: 15372 | Write file or device (Write 25 bytes on handle 1)
2018-12-17T22:28:09.465419763Z 64 PC: 15372 | Write file or device (Write 35 bytes on handle 1)
2018-12-17T22:28:09.471986758Z 64 PC: 15372 | Write file or device (Write 17 bytes on handle 1)
2018-12-17T22:28:09.476477284Z 64 PC: 15372 | Write file or device (Write 23 bytes on handle 1)
2018-12-17T22:28:09.482738434Z 7 PC: 13b46 | Direct console input without echo