Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Shadowgard

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:27.548752012Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:27.551025372Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:42:27.552464195Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:42:27.554070893Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:27.555931317Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:27.557580193Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:27.559237536Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:42:27.560914626Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:42:27.563142Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:42:27.564840389Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:42:27.566460292Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:42:27.569044957Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:42:27.570510209Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:42:27.571980811Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:42:27.57399299Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:42:27.575695588Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:42:27.577235109Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:42:27.579727701Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:42:27.581212118Z 53 PC: 13cc2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:42:27.582549981Z 37 PC: 13cd7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:27.584034309Z 37 PC: 13cdf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:27.585709646Z 37 PC: 13ce7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:27.586974802Z 37 PC: 13cef | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:42:27.58885884Z 68 PC: 1405f | I/O control for devices (Set for = '')
2018-12-17T22:42:27.591528916Z 54 PC: 13b1a | Get free disk space
2018-12-17T22:42:27.601468815Z 48 PC: 147d1 | Get DOS version
2018-12-17T22:42:27.608598505Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.612322129Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.615375023Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.618487128Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.622973534Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.626298329Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.629715016Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.634652199Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.638495407Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.641806837Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.645979984Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.649419094Z 64 PC: 14162 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:42:27.652748297Z 64 PC: 14162 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:42:27.65843628Z 64 PC: 14162 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:42:27.660956102Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:27.662436563Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:42:27.664139472Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:42:27.665637916Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:27.666737912Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:27.667895777Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:27.669864514Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:42:27.671275895Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:42:27.672708386Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:42:27.675023704Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:42:27.68219844Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:42:27.68334871Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:42:27.685637268Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:42:27.687028591Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:42:27.688429884Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:42:27.690486707Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:42:27.691810493Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:42:27.692968858Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:42:27.695203275Z 37 PC: 13dd6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:42:27.696439768Z 76 PC: 13e15 | Terminate with return code (Return code = '1')