Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Nova

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:41.990329493Z 53 PC: 13aea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:41.992691586Z 53 PC: 13aea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:41.995585164Z 53 PC: 13aea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:41.997300968Z 53 PC: 13aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:42.00019393Z 53 PC: 13aea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:42.002054159Z 53 PC: 13aea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:42.003783295Z 53 PC: 13aea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:42.005623138Z 53 PC: 13aea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:42.008059849Z 53 PC: 13aea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:42.009590009Z 53 PC: 13aea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:42.0110885Z 53 PC: 13aea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:42.013039066Z 53 PC: 13aea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:42.014318141Z 53 PC: 13aea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:42.015598119Z 53 PC: 13aea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:42.017876524Z 53 PC: 13aea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:42.019600997Z 53 PC: 13aea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:42.022118085Z 53 PC: 13aea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:42.02875452Z 53 PC: 13aea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:42.030267655Z 53 PC: 13aea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:42.031666812Z 37 PC: 13aff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:42.033289627Z 37 PC: 13b07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:42.035736033Z 37 PC: 13b0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:42.037330824Z 37 PC: 13b17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:42.039557931Z 68 PC: 14768 | I/O control for devices (Set for = '')
2018-12-17T22:31:42.146519375Z 37 PC: 134a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:42.148052959Z 53 PC: 133dd | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:42.1491368Z 37 PC: 133f9 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:42.15098043Z 44 PC: 15073 | Get time 0x15073: mov word ptr [0x54a], cx
0x15077: mov word ptr [0x54c], dx
0x1507b: retf
0x1507c: mov di, 0x55e
0x1507f: push ds
0x15080: pop es
0x15081: mov cx, 0x38fc
0x15084: sub cx, di
0x15086: shr cx, 1
0x15088: xor ax, ax
0x1508a: cld
0x1508b: rep stosd dword ptr es:[di], eax
0x1508d: ret
0x1508e: add byte ptr [bx + si], al
0x15090: add byte ptr [bx + si], al
0x15092: add byte ptr [bx + di], al
0x15094: inc di
0x15095: and byte ptr [bx + si], ah
0x15097: and byte ptr [bx + si], ah
0x15099: and byte ptr [bx + si], ah
2018-12-17T22:31:42.153334586Z 48 PC: 143a8 | Get DOS version
2018-12-17T22:31:42.154687988Z 67 PC: 1336b | Get or set file attributes
2018-12-17T22:31:42.170869179Z 61 PC: 141e6 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:31:42.175733251Z 63 PC: 142b9 | Read file or device (Read 12288 bytes on handle 5)
2018-12-17T22:31:42.180981315Z 62 PC: 14236 | Close file
2018-12-17T22:31:42.185263381Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:31:42.186661327Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:31:42.187836596Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:31:42.189604492Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:42.190711742Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:42.207254017Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:42.209449193Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:31:42.211059814Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:31:42.212368292Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:31:42.213934221Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:31:42.215813387Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:31:42.217036797Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:31:42.218158604Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:31:42.220172928Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:31:42.22114655Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:31:42.222068882Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:31:42.224205492Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:31:42.225654076Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:31:42.231133141Z 37 PC: 13c41 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:31:42.234242848Z 76 PC: 13c80 | Terminate with return code (Return code = '0')