Sample viewer

vx.netlux.org/Virus.DOS.HLLO.3008

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:49.327484801Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:49.329538291Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:49.331038375Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:49.332407528Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:49.333793056Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:49.350526305Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:49.351726316Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:49.352957715Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:49.354884511Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:49.356068881Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:49.358314989Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:49.360736344Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:49.36237798Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:49.363636146Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:49.365474417Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:49.366691405Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:49.367708647Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:49.369279972Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:49.370532634Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:49.371773117Z 37 PC: 12e07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:49.373379749Z 37 PC: 12e0f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:49.374729674Z 37 PC: 12e17 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:49.375912084Z 37 PC: 12e1f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:49.377722269Z 68 PC: 1318f | I/O control for devices (Set for = '')
2018-12-17T22:32:49.379401431Z 48 PC: 13477 | Get DOS version
2018-12-17T22:32:49.381026887Z 67 PC: 12c9f | Get or set file attributes
2018-12-17T22:32:49.387564137Z 67 PC: 12cc6 | Get or set file attributes
2018-12-17T22:32:49.407810842Z 61 PC: 13329 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:32:49.415653651Z 63 PC: 133fc | Read file or device (Read 3008 bytes on handle 5)
2018-12-17T22:32:49.424194466Z 67 PC: 12cc6 | Get or set file attributes
2018-12-17T22:32:49.435855367Z 62 PC: 13379 | Close file
2018-12-17T22:32:49.43850937Z 26 PC: 12d3d | Set disk transfer address
2018-12-17T22:32:49.439596359Z 78 PC: 12d49 | Find first file
2018-12-17T22:32:49.450179445Z 67 PC: 12c9f | Get or set file attributes
2018-12-17T22:32:49.45412208Z 67 PC: 12cc6 | Get or set file attributes
2018-12-17T22:32:49.461260229Z 61 PC: 13329 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:32:49.469306902Z 63 PC: 133fc | Read file or device (Read 3008 bytes on handle 5)
2018-12-17T22:32:49.477469105Z 67 PC: 12cc6 | Get or set file attributes
2018-12-17T22:32:49.492556664Z 62 PC: 13379 | Close file
2018-12-17T22:32:49.505602731Z 26 PC: 12d61 | Set disk transfer address
2018-12-17T22:32:49.506914265Z 79 PC: 12d66 | Find next file
2018-12-17T22:32:49.510009679Z 64 PC: 13292 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:32:49.513055005Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:49.515507279Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:49.518422127Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:49.521474012Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:49.523370663Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:49.525069284Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:49.526767165Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:49.528415244Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:49.529462518Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:49.530523588Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:49.532568521Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:49.534243225Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:49.536109444Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:49.538352996Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:49.539711781Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:49.541048652Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:49.543024181Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:49.544255808Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:49.546080599Z 37 PC: 12f06 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:49.548011926Z 76 PC: 12f45 | Terminate with return code (Return code = '0')