Sample viewer

vx.netlux.org/Virus.DOS.HLLO.DeadByte.3568

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:01.495565995Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:01.497272618Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:01.500072358Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:01.503325553Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:01.505800879Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:01.508613612Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:01.510097185Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:01.512019857Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:01.516381286Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:01.518168082Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:01.5197609Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:01.521838134Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:01.523355531Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:01.524733314Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:01.526450789Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:01.531230928Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:01.532461212Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:01.53392091Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:01.535551991Z 53 PC: 12d3a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:01.537018802Z 37 PC: 12d4f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:01.538323477Z 37 PC: 12d57 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:01.551136702Z 37 PC: 12d5f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:01.552470602Z 37 PC: 12d67 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:01.554161706Z 68 PC: 13682 | I/O control for devices (Set for = 'I��Q��Y&:� &:u�, &:u�G���p�&�>>�}< w�< t�]�< u��V��&�')
2018-12-17T22:39:01.557566658Z 60 PC: 13666 | Create or truncate file
2018-12-17T22:39:01.57571913Z 68 PC: 13682 | I/O control for devices (Set for = 'I��Q��Y&:� &:u�, &:u�G���p�&�>>�}< w�< t�]�< u��V��&�')
2018-12-17T22:39:01.577646972Z 64 PC: 130d8 | Write file or device (Write 35 bytes on handle 5)
2018-12-17T22:39:01.581720356Z 62 PC: 13117 | Close file
2018-12-17T22:39:01.588336124Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:01.589511795Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:01.591708184Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:01.598190039Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:01.600257194Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:01.60324066Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:01.604885697Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:01.60667098Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:01.608737284Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:01.610182995Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:01.611367793Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:01.612792083Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:01.614967022Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:01.616520206Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:01.618046709Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:01.621652892Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:01.623943038Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:01.625946332Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:01.630376732Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:01.632036878Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:01.63392255Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:01.636281567Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:01.637721346Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:01.639424173Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:01.642050735Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:01.643923783Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:01.646601492Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:01.648644491Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:01.651235275Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:01.653015898Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:01.654670915Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:01.658913971Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:01.661584315Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:01.664209033Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:01.666467129Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:01.66846839Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:01.670516038Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:01.689438243Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:01.699501423Z 48 PC: 133a8 | Get DOS version
2018-12-17T22:39:01.702480711Z 41 PC: 12c6f | Parse filename
2018-12-17T22:39:01.70483567Z 41 PC: 12c7d | Parse filename
2018-12-17T22:39:01.70681028Z 75 PC: 12c88 | Execute program
2018-12-17T22:39:01.729961585Z 80 PC: 16d69 | Set current PSP
2018-12-17T22:39:01.73174816Z 48 PC: 16d6e | Get DOS version
2018-12-17T22:39:01.733861893Z 99 PC: 1d550 | Get DBCS lead byte table pointer
2018-12-17T22:39:01.737284959Z 101 PC: 16df4 | Get extended country info
2018-12-17T22:39:01.739724107Z 99 PC: 16dfa | Get DBCS lead byte table pointer
2018-12-17T22:39:01.741479273Z 74 PC: 16e5c | Reallocate memory
2018-12-17T22:39:01.743398648Z 25 PC: 16e93 | Get default drive
2018-12-17T22:39:01.74522563Z 37 PC: 16953 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:39:01.74704168Z 37 PC: 1695a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:01.748459047Z 37 PC: 16961 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:01.754173834Z 74 PC: 15afc | Reallocate memory
2018-12-17T22:39:01.7567395Z 72 PC: 15b3d | Allocate memory
2018-12-17T22:39:01.758840509Z 72 PC: 15b75 | Allocate memory
2018-12-17T22:39:01.761062105Z 72 PC: 15b7d | Allocate memory