Sample viewer

vx.netlux.org/Virus.DOS.HLLO.4752

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:56.696982276Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:56.69885708Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:56.700242248Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:56.70135231Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:56.702935308Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:56.706361511Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:56.707597987Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:56.709207551Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:56.711240288Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:56.713240955Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:56.715697207Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:56.726135674Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:56.728089931Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:56.729480738Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:56.734159942Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:56.735299841Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:56.736391173Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:56.738703968Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:56.74011689Z 53 PC: 12f2a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:56.741556119Z 37 PC: 12f3f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:56.744644294Z 37 PC: 12f47 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:56.745810989Z 37 PC: 12f4f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:56.747391503Z 37 PC: 12f57 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:56.749883254Z 68 PC: 13a13 | I/O control for devices (Set for = '')
2018-12-17T22:34:56.751745479Z 26 PC: 12dab | Set disk transfer address
2018-12-17T22:34:56.753162988Z 78 PC: 12db7 | Find first file
2018-12-17T22:34:56.759914872Z 25 PC: 12e31 | Get default drive
2018-12-17T22:34:56.761369959Z 71 PC: 12e50 | Get current directory
2018-12-17T22:34:56.764800181Z 48 PC: 1373e | Get DOS version
2018-12-17T22:34:56.767173643Z 26 PC: 12dcf | Set disk transfer address
2018-12-17T22:34:56.76840662Z 79 PC: 12dd4 | Find next file
2018-12-17T22:34:56.770828484Z 26 PC: 12dcf | Set disk transfer address
2018-12-17T22:34:56.77219872Z 79 PC: 12dd4 | Find next file
2018-12-17T22:34:56.775295583Z 44 PC: 13b4a | Get time 0x13b4a: mov word ptr [0x42], cx
0x13b4e: mov word ptr [0x44], dx
0x13b52: retf
0x13b53: mov di, 0x56
0x13b56: push ds
0x13b57: pop es
0x13b58: mov cx, 0x166a
0x13b5b: sub cx, di
0x13b5d: shr cx, 1
0x13b5f: xor ax, ax
0x13b61: cld
0x13b62: rep stosd dword ptr es:[di], eax
0x13b64: ret
0x13b65: add byte ptr [bx + si], al
0x13b67: add byte ptr [bx + si], al
0x13b69: add byte ptr [bx + si], al
0x13b6b: add byte ptr [bx + si], al
0x13b6d: add byte ptr [bx + si], al
0x13b6f: add byte ptr [bx + si], al
0x13b71: add byte ptr [si + 0x55], dl
2018-12-17T22:34:56.778560013Z 64 PC: 13348 | Write file or device (Write 28 bytes on handle 1)
2018-12-17T22:34:56.78373311Z 64 PC: 13348 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:34:56.786285163Z 37 PC: 13081 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:56.787490173Z 37 PC: 13081 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:56.788894518Z 37 PC: 13081 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:56.790904059Z 37 PC: 13081 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:56.792385619Z 37 PC: 13081 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:56.793848883Z 37 PC: 13081 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:56.795788715Z 37 PC: 13081 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:56.797238635Z 37 PC: 13081 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:56.79868234Z 37 PC: 13081 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:56.801060322Z 37 PC: 13081 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:56.802449245Z 37 PC: 13081 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:56.803818204Z 37 PC: 13081 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:56.806184906Z 37 PC: 13081 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:56.80784975Z 37 PC: 13081 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:56.809172438Z 37 PC: 13081 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:56.810889843Z 37 PC: 13081 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:56.812057345Z 37 PC: 13081 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:56.813545593Z 37 PC: 13081 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:56.815406813Z 37 PC: 13081 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:56.816411704Z 76 PC: 130c0 | Terminate with return code (Return code = '0')