Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Bestia.13418

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:23.334002447Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:35:23.335706865Z 53 PC: 12bf2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:23.337130555Z 53 PC: 12bff | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:35:23.339240423Z 53 PC: 12c0c | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:35:23.340674797Z 53 PC: 12c19 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:35:23.341817766Z 37 PC: 12c2d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:23.343565387Z 74 PC: 12af7 | Reallocate memory
2018-12-17T22:35:23.346535304Z 68 PC: 13013 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:35:23.349119618Z 68 PC: 13013 | I/O control for devices (Set for = '')
2018-12-17T22:35:23.353946142Z 67 PC: 13bcd | Get or set file attributes
2018-12-17T22:35:23.360489002Z 61 PC: 143d7 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:23.367591592Z 68 PC: 13817 | I/O control for devices (Set for = '')
2018-12-17T22:35:23.36966306Z 68 PC: 13013 | I/O control for devices
2018-12-17T22:35:23.371717556Z 47 PC: 12edc | Get disk transfer address
2018-12-17T22:35:23.373691776Z 26 PC: 12ee5 | Set disk transfer address
2018-12-17T22:35:23.374665252Z 78 PC: 12eef | Find first file
2018-12-17T22:35:23.378821859Z 26 PC: 12ef8 | Set disk transfer address
2018-12-17T22:35:23.380320939Z 47 PC: 12f0f | Get disk transfer address
2018-12-17T22:35:23.381672501Z 26 PC: 12f18 | Set disk transfer address
2018-12-17T22:35:23.383241177Z 79 PC: 12f1c | Find next file
2018-12-17T22:35:23.384833473Z 26 PC: 12f25 | Set disk transfer address
2018-12-17T22:35:23.385960736Z 62 PC: 13c08 | Close file
2018-12-17T22:35:23.388149459Z 37 PC: 12c39 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:23.389073398Z 37 PC: 12c44 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:35:23.389998997Z 37 PC: 12c4f | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:35:23.391414729Z 37 PC: 12c5a | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:35:23.39251769Z 62 PC: 13c08 | Close file
2018-12-17T22:35:23.393969033Z 62 PC: 13c08 | Close file
2018-12-17T22:35:23.39733778Z 62 PC: 13c08 | Close file
2018-12-17T22:35:23.398815251Z 62 PC: 13c08 | Close file
2018-12-17T22:35:23.40082276Z 62 PC: 13c08 | Close file
2018-12-17T22:35:23.403092576Z 76 PC: 12be3 | Terminate with return code (Return code = '0')