Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Not.17923

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:41.447766944Z 53 PC: 13272 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:41.450252052Z 53 PC: 13272 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:41.451933009Z 53 PC: 13272 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:41.453584882Z 53 PC: 13272 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:41.45695446Z 53 PC: 13272 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:41.458936052Z 53 PC: 13272 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:41.460328738Z 53 PC: 13272 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:41.461746511Z 53 PC: 13272 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:41.464213153Z 53 PC: 13272 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:41.466179356Z 53 PC: 13272 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:41.46810843Z 53 PC: 13272 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:41.470861861Z 53 PC: 13272 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:41.472495399Z 53 PC: 13272 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:41.474129297Z 53 PC: 13272 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:41.47636721Z 53 PC: 13272 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:41.477965282Z 53 PC: 13272 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:41.479608388Z 53 PC: 13272 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:41.482382909Z 53 PC: 13272 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:41.483919164Z 53 PC: 13272 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:41.485182497Z 37 PC: 13287 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:41.488291887Z 37 PC: 1328f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:41.490449961Z 37 PC: 13297 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:41.492597644Z 37 PC: 1329f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:41.506972723Z 68 PC: 1381f | I/O control for devices (Set for = '')
2018-12-17T22:43:41.510166061Z 26 PC: 130ed | Set disk transfer address
2018-12-17T22:43:41.511372226Z 78 PC: 130f9 | Find first file
2018-12-17T22:43:41.51849836Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.521352711Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.525943783Z 61 PC: 13c74 | Open file (Filename = '\SLEEP.COM')
2018-12-17T22:43:41.533169074Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.536547389Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.53840065Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.540265021Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.542726835Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.544769792Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.546293744Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.551758077Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.553363282Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.556916245Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.559214492Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.563836042Z 61 PC: 13c74 | Open file (Filename = '\PRINT.COM')
2018-12-17T22:43:41.570983506Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.573339109Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.575427031Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.577129349Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.579340391Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.581401502Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.582676898Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.585986163Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.587711263Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.591913135Z 61 PC: 13c74 | Open file (Filename = '\HELLO.COM')
2018-12-17T22:43:41.598828934Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.601617461Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.603553608Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.605662238Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.608155761Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.610149366Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.611298093Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.617135547Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.620048327Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.625198851Z 61 PC: 13c74 | Open file (Filename = '\PHANG.COM')
2018-12-17T22:43:41.633846814Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.636212767Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.638444889Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.641009667Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.643139296Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.64524959Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.648091377Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.652124873Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.65390168Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.657770556Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.660650475Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.665683919Z 61 PC: 13c74 | Open file (Filename = '\PRINTA~1.COM')
2018-12-17T22:43:41.67302168Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.675967302Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.678131577Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.680171829Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.682873063Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.684854023Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.685973826Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.689853203Z 61 PC: 13c74 | Open file (Filename = '\MANDEL.COM')
2018-12-17T22:43:41.694984109Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.696259454Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.698133594Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.699536559Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.701379341Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.70633092Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.707531616Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.711684145Z 61 PC: 13c74 | Open file (Filename = '\PAH.COM')
2018-12-17T22:43:41.718752992Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.721374124Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.723279583Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.725137472Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.727949063Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.730165316Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.731625137Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.737178488Z 61 PC: 13c74 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:43:41.744595948Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:41.746682577Z 66 PC: 13e10 | Move file pointer
2018-12-17T22:43:41.749408537Z 66 PC: 13e1e | Move file pointer
2018-12-17T22:43:41.751756707Z 66 PC: 13e2c | Move file pointer
2018-12-17T22:43:41.753913458Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.757283949Z 26 PC: 13111 | Set disk transfer address
2018-12-17T22:43:41.758996054Z 79 PC: 13116 | Find next file
2018-12-17T22:43:41.76221492Z 60 PC: 13c74 | Create or truncate file
2018-12-17T22:43:41.781629764Z 61 PC: 13c74 | Open file (Filename = 'V1-NOT!.EXE')
2018-12-17T22:43:41.790134487Z 64 PC: 13d47 | Write file or device (Write 16768 bytes on handle 5)
2018-12-17T22:43:41.800077983Z 62 PC: 13cc4 | Close file
2018-12-17T22:43:41.809011582Z 53 PC: 13154 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:41.811498473Z 37 PC: 1315d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:41.812972822Z 53 PC: 13154 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:41.814471567Z 37 PC: 1315d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:41.816704961Z 53 PC: 13154 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:41.818181013Z 37 PC: 1315d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:41.819575973Z 53 PC: 13154 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:41.821887575Z 37 PC: 1315d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:41.823284038Z 53 PC: 13154 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:41.82469608Z 37 PC: 1315d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:41.827830958Z 53 PC: 13154 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:41.829283906Z 37 PC: 1315d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:41.830703803Z 53 PC: 13154 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:41.832336069Z 37 PC: 1315d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:41.834715688Z 53 PC: 13154 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:41.836220875Z 37 PC: 1315d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:41.8377034Z 53 PC: 13154 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:41.840414893Z 37 PC: 1315d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:41.841894832Z 53 PC: 13154 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:41.843307726Z 37 PC: 1315d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:41.845497969Z 53 PC: 13154 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:41.847152487Z 37 PC: 1315d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:41.848707337Z 53 PC: 13154 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:41.851347195Z 37 PC: 1315d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:41.853038101Z 53 PC: 13154 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:41.854482434Z 37 PC: 1315d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:41.856629526Z 53 PC: 13154 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:41.858298761Z 37 PC: 1315d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:41.860285603Z 53 PC: 13154 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:41.862943004Z 37 PC: 1315d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:41.864453992Z 53 PC: 13154 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:41.866004644Z 37 PC: 1315d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:41.86871793Z 53 PC: 13154 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:41.870282057Z 37 PC: 1315d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:41.871639748Z 53 PC: 13154 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:41.874145815Z 37 PC: 1315d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:41.875525506Z 53 PC: 13154 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:41.876877194Z 37 PC: 1315d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:41.878950338Z 41 PC: 131dd | Parse filename
2018-12-17T22:43:41.880449885Z 41 PC: 131eb | Parse filename
2018-12-17T22:43:41.881904617Z 75 PC: 131f6 | Execute program