Sample viewer

vx.netlux.org/Virus.DOS.Hanko.4167

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:55.919480965Z 237 PC: 134f3 | UNKNOWN!
2018-12-17T22:38:55.921591226Z 53 PC: 12ada | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:55.923291501Z 53 PC: 12ada | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:55.924910232Z 53 PC: 12ada | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:55.926800396Z 53 PC: 12ada | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:55.928314379Z 53 PC: 12ada | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:55.929651197Z 53 PC: 12ada | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:55.930967567Z 53 PC: 12ada | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:55.932620342Z 53 PC: 12ada | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:55.934250355Z 53 PC: 12ada | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:55.935881459Z 53 PC: 12ada | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:55.938533474Z 53 PC: 12ada | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:55.939540509Z 53 PC: 12ada | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:55.940441021Z 53 PC: 12ada | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:55.941860886Z 53 PC: 12ada | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:55.942780055Z 53 PC: 12ada | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:55.943702299Z 53 PC: 12ada | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:55.944961961Z 53 PC: 12ada | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:55.945875458Z 53 PC: 12ada | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:55.94677543Z 53 PC: 12ada | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:55.948025474Z 37 PC: 12aef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:55.94890092Z 37 PC: 12af7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:55.949748563Z 37 PC: 12aff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:55.951112472Z 37 PC: 12b07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:55.952326347Z 68 PC: 13165 | I/O control for devices (Set for = 'h�&�>�t���-&�n$P3�&���t&�&�>�t��&�')
2018-12-17T22:38:55.953637036Z 64 PC: 12ef8 | Write file or device (Write 2870542346 bytes on handle 1)
2018-12-17T22:38:55.956931245Z 64 PC: 12ef8 | Write file or device (Write 2870542336 bytes on handle 1)
2018-12-17T22:38:55.958544667Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:55.95945578Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:55.960464347Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:55.961803479Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:55.962673204Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:55.963531968Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:55.964716118Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:55.965587596Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:55.966440278Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:55.96758359Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:55.968489232Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:55.96935518Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:55.970562844Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:55.97147056Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:55.972349051Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:55.973716608Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:55.974671443Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:55.975569001Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:55.976963458Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:55.977909056Z 76 PC: 12c70 | Terminate with return code (Return code = '0')