Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Install.4578

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:11.801935805Z 53 PC: 12faa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:11.804898452Z 53 PC: 12faa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:30:11.807251704Z 53 PC: 12faa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:11.809362341Z 53 PC: 12faa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:11.811976125Z 53 PC: 12faa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:11.813993628Z 53 PC: 12faa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:11.815767644Z 53 PC: 12faa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:30:11.817884263Z 53 PC: 12faa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:30:11.821252133Z 53 PC: 12faa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:30:11.823320244Z 53 PC: 12faa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:30:11.825379563Z 53 PC: 12faa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:30:11.828151368Z 53 PC: 12faa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:30:11.853732401Z 53 PC: 12faa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:30:11.856510766Z 53 PC: 12faa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:30:11.859672145Z 53 PC: 12faa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:30:11.861846567Z 53 PC: 12faa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:30:11.863491277Z 53 PC: 12faa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:30:11.881219003Z 53 PC: 12faa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:11.882555341Z 53 PC: 12faa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:30:11.883819666Z 37 PC: 12fbf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:11.885498678Z 37 PC: 12fc7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:11.887988823Z 37 PC: 12fcf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:11.889704533Z 37 PC: 12fd7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:11.892067851Z 68 PC: 13eba | I/O control for devices (Set for = '�K��>C�')
2018-12-17T22:30:11.894054211Z 48 PC: 13acb | Get DOS version
2018-12-17T22:30:11.895963425Z 61 PC: 13909 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:30:11.903291937Z 66 PC: 13fb9 | Move file pointer
2018-12-17T22:30:11.905203531Z 66 PC: 13fc7 | Move file pointer
2018-12-17T22:30:11.907046973Z 66 PC: 13fd5 | Move file pointer
2018-12-17T22:30:11.909495092Z 63 PC: 139dc | Read file or device (Read 5952 bytes on handle 5)
2018-12-17T22:30:11.932728257Z 62 PC: 13959 | Close file
2018-12-17T22:30:11.93566063Z 60 PC: 13909 | Create or truncate file
2018-12-17T22:30:11.954288329Z 64 PC: 139dc | Write file or device (Write 5952 bytes on handle 5)
2018-12-17T22:30:11.969651608Z 62 PC: 13959 | Close file
2018-12-17T22:30:11.978329821Z 26 PC: 12db5 | Set disk transfer address
2018-12-17T22:30:11.979926717Z 78 PC: 12dc1 | Find first file
2018-12-17T22:30:11.990302233Z 26 PC: 12db5 | Set disk transfer address
2018-12-17T22:30:11.991728344Z 78 PC: 12dc1 | Find first file
2018-12-17T22:30:11.998706491Z 26 PC: 12db5 | Set disk transfer address
2018-12-17T22:30:12.001316268Z 78 PC: 12dc1 | Find first file
2018-12-17T22:30:12.00764653Z 60 PC: 13909 | Create or truncate file
2018-12-17T22:30:12.020085143Z 64 PC: 139dc | Write file or device (Write 5952 bytes on handle 5)
2018-12-17T22:30:12.032549348Z 62 PC: 13959 | Close file
2018-12-17T22:30:12.04061276Z 26 PC: 12dd9 | Set disk transfer address
2018-12-17T22:30:12.041790423Z 79 PC: 12dde | Find next file
2018-12-17T22:30:12.045427257Z 60 PC: 13909 | Create or truncate file
2018-12-17T22:30:12.056962749Z 64 PC: 139dc | Write file or device (Write 5952 bytes on handle 5)
2018-12-17T22:30:12.066463539Z 62 PC: 13959 | Close file
2018-12-17T22:30:12.075392904Z 26 PC: 12dd9 | Set disk transfer address
2018-12-17T22:30:12.07691895Z 79 PC: 12dde | Find next file
2018-12-17T22:30:12.079942174Z 65 PC: 13a52 | Delete file (Filename = '� ��6p�6nj')
2018-12-17T22:30:12.091733009Z 64 PC: 135d0 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:30:12.096774881Z 64 PC: 135d0 | Write file or device (Write 31 bytes on handle 1)
2018-12-17T22:30:12.101792913Z 64 PC: 135d0 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:30:12.107414602Z 64 PC: 135d0 | Write file or device (Write 15 bytes on handle 1)
2018-12-17T22:30:12.112395561Z 64 PC: 135d0 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:30:12.114334154Z 37 PC: 13101 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:12.116270604Z 37 PC: 13101 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:30:12.117952596Z 37 PC: 13101 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:12.119313935Z 37 PC: 13101 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:12.120884876Z 37 PC: 13101 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:12.123024912Z 37 PC: 13101 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:12.124226828Z 37 PC: 13101 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:30:12.125566582Z 37 PC: 13101 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:30:12.128035042Z 37 PC: 13101 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:30:12.129327624Z 37 PC: 13101 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:30:12.130592993Z 37 PC: 13101 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:30:12.132496512Z 37 PC: 13101 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:30:12.133854883Z 37 PC: 13101 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:30:12.135181432Z 37 PC: 13101 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:30:12.13732499Z 37 PC: 13101 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:30:12.139422743Z 37 PC: 13101 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:30:12.140750721Z 37 PC: 13101 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:30:12.142411181Z 37 PC: 13101 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:12.143823598Z 37 PC: 13101 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:30:12.145629691Z 76 PC: 13140 | Terminate with return code (Return code = '0')