Sample viewer

vx.netlux.org/Virus.DOS.Hellfire.1101

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:08.766321437Z 37 PC: 12a4c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:08.768045355Z 78 PC: 12a55 | Find first file
2018-12-17T22:33:08.774413992Z 61 PC: 12a5f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:33:08.781323149Z 63 PC: 12a6a | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:33:08.787715191Z 62 PC: 12a6e | Close file
2018-12-17T22:33:08.78976315Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:33:08.80124819Z 44 PC: 12a84 | Get time 0x12a84: mov word ptr [0x549], dx
0x12a88: mov ah, 0x40
0x12a8a: push ax
0x12a8b: mov cx, 0x44d
0x12a8e: push cx
0x12a8f: mov dx, 0x100
0x12a92: jmp 0x12e6b
0x12a95: mov ah, 9
0x12a97: mov dx, 0x1e1
0x12a9a: int 0x21
0x12a9c: int 0x20
0x12a9e: mov ah, 0xf
0x12aa0: int 0x10
0x12aa2: xor ah, ah
0x12aa4: int 0x10
0x12aa6: mov ah, 1
0x12aa8: mov cx, 0x2607
0x12aab: int 0x10
0x12aad: mov ax, 0xb800
0x12ab0: mov es, ax
2018-12-17T22:33:08.803380535Z 64 PC: 12e72 | Write file or device (Write 1101 bytes on handle 5)
2018-12-17T22:33:08.835834678Z 9 PC: 12a9c | Display string (String= 'Bad command or file name ')