Sample viewer

vx.netlux.org/Virus.DOS.HLLO.10579

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:56:40.874466778Z 48 PC: 12b4b | Get DOS version
2018-12-17T21:56:40.87648469Z 53 PC: 12cca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:56:40.877543008Z 53 PC: 12cd7 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:56:40.878577201Z 53 PC: 12ce4 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:56:40.880627389Z 53 PC: 12cf1 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:56:40.881688145Z 37 PC: 12d05 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:56:40.882842529Z 74 PC: 12bf6 | Reallocate memory
2018-12-17T21:56:40.884720162Z 68 PC: 130c2 | I/O control for devices (Set for = '')
2018-12-17T21:56:40.886477879Z 68 PC: 130c2 | I/O control for devices (Set for = '')
2018-12-17T21:56:40.888438995Z 67 PC: 1363b | Get or set file attributes
2018-12-17T21:56:40.894021409Z 61 PC: 13aa2 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:56:40.900809526Z 68 PC: 13277 | I/O control for devices (Set for = '')
2018-12-17T21:56:40.902199377Z 66 PC: 13719 | Move file pointer
2018-12-17T21:56:40.90346685Z 66 PC: 13726 | Move file pointer
2018-12-17T21:56:40.905069499Z 66 PC: 13735 | Move file pointer
2018-12-17T21:56:40.906673284Z 63 PC: 13114 | Read file or device (Read 10579 bytes on handle 5)
2018-12-17T21:56:40.914382587Z 62 PC: 13676 | Close file
2018-12-17T21:56:40.916675078Z 53 PC: 13056 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:56:40.91848065Z 37 PC: 13069 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:56:40.919617453Z 53 PC: 13056 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:56:40.92149842Z 37 PC: 13069 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:56:40.922650019Z 37 PC: 12d11 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:56:40.923873195Z 37 PC: 12d1c | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:56:40.925404413Z 37 PC: 12d27 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:56:40.926478393Z 37 PC: 12d32 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:56:40.927517425Z 49 PC: 1329b | Terminate and stay resident (Return code = '0' | Memory size = '1000')