Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Destroy.4592

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:26.225457499Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:26.227618426Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:26.228798429Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:26.229992524Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:26.231768465Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:26.232951703Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:26.234263329Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:26.245680415Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:26.247108979Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:26.248479783Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:26.250579763Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:26.252024452Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:26.253530517Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:26.25494792Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:26.257161637Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:26.258580154Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:26.259971374Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:26.271054833Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:26.272203435Z 53 PC: 130e2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:26.273334907Z 37 PC: 130f7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:26.275348999Z 37 PC: 130ff | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:26.276692027Z 37 PC: 13107 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:26.27804999Z 37 PC: 1310f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:26.280616734Z 68 PC: 1342c | I/O control for devices (Set for = '')
2018-12-17T22:45:26.282283153Z 44 PC: 137e2 | Get time 0x137e2: mov word ptr [0x3e], cx
0x137e6: mov word ptr [0x40], dx
0x137ea: retf
0x137eb: mov bx, sp
0x137ed: push ds
0x137ee: les di, ptr ss:[bx + 8]
0x137f2: lds si, ptr ss:[bx + 4]
0x137f6: cld
0x137f7: xor ax, ax
0x137f9: stosw word ptr es:[di], ax
0x137fa: mov ax, 0xd7b0
0x137fd: stosw word ptr es:[di], ax
0x137fe: xor ax, ax
0x13800: mov cx, 0x16
0x13803: rep stosd dword ptr es:[di], eax
0x13805: lodsb al, byte ptr [si]
0x13806: cmp al, 0x4f
0x13808: jbe 0x1380c
0x1380a: mov al, 0x4f
0x1380c: mov cl, al
2018-12-17T22:45:26.285471859Z 42 PC: 12f65 | Get date 0x12f65: pushf
0x12f66: push es
0x12f67: push di
0x12f68: push bp
0x12f69: mov bp, sp
0x12f6b: les di, ptr [bp + 0x10]
0x12f6e: cld
0x12f6f: stosw word ptr es:[di], ax
0x12f70: mov ax, bx
0x12f72: stosw word ptr es:[di], ax
0x12f73: mov ax, cx
0x12f75: stosw word ptr es:[di], ax
0x12f76: mov ax, dx
0x12f78: stosw word ptr es:[di], ax
0x12f79: pop ax
0x12f7a: stosw word ptr es:[di], ax
0x12f7b: mov ax, si
0x12f7d: stosw word ptr es:[di], ax
0x12f7e: pop ax
0x12f7f: stosw word ptr es:[di], ax
2018-12-17T22:45:26.297630331Z 25 PC: 13a3c | Get default drive
2018-12-17T22:45:26.299129864Z 71 PC: 13a4f | Get current directory
2018-12-17T22:45:26.302125643Z 25 PC: 12b6d | Get default drive
2018-12-17T22:45:26.303862317Z 48 PC: 139af | Get DOS version
2018-12-17T22:45:26.305363318Z 61 PC: 13861 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:45:26.312072711Z 63 PC: 13934 | Read file or device (Read 4592 bytes on handle 5)
2018-12-17T22:45:26.320335526Z 62 PC: 138b1 | Close file
2018-12-17T22:45:26.322599096Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T22:45:26.323707651Z 78 PC: 12fbd | Find first file
2018-12-17T22:45:26.330435161Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.331605755Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.334376946Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.336067136Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.338848385Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.339902929Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.342701873Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.356267515Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.359018238Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.36031484Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.363433058Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.364726901Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.368606834Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.370992721Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.373984223Z 61 PC: 13861 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:45:26.387330747Z 43 PC: 12f65 | Set date
2018-12-17T22:45:26.395067844Z 64 PC: 13934 | Write file or device (Write 4592 bytes on handle 5)
2018-12-17T22:45:26.421672814Z 62 PC: 138b1 | Close file
2018-12-17T22:45:26.430343363Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T22:45:26.432397626Z 78 PC: 12fbd | Find first file
2018-12-17T22:45:26.451022046Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.452104231Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.455263998Z 61 PC: 13861 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:45:26.463751223Z 43 PC: 12f65 | Set date
2018-12-17T22:45:26.473926559Z 64 PC: 13934 | Write file or device (Write 4592 bytes on handle 5)
2018-12-17T22:45:26.510116105Z 62 PC: 138b1 | Close file
2018-12-17T22:45:26.518294496Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T22:45:26.519854907Z 78 PC: 12fbd | Find first file
2018-12-17T22:45:26.542471568Z 14 PC: 12f65 | Set default drive (Drive = 'A')
2018-12-17T22:45:26.544236477Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T22:45:26.54547315Z 78 PC: 12fbd | Find first file
2018-12-17T22:45:26.552329662Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.553552822Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.565829545Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.569075101Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.571959834Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.57317275Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.576845683Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.57808696Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.580871795Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.582735026Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.585537515Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.594275562Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.598429544Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.599663061Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.602509512Z 61 PC: 13861 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:45:26.622534543Z 43 PC: 12f65 | Set date
2018-12-17T22:45:26.625940383Z 64 PC: 13934 | Write file or device (Write 4592 bytes on handle 5)
2018-12-17T22:45:26.635042358Z 62 PC: 138b1 | Close file
2018-12-17T22:45:26.643338912Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T22:45:26.645596303Z 78 PC: 12fbd | Find first file
2018-12-17T22:45:26.652145908Z 26 PC: 12fd5 | Set disk transfer address
2018-12-17T22:45:26.653450691Z 79 PC: 12fda | Find next file
2018-12-17T22:45:26.657191692Z 61 PC: 13861 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:45:26.664062793Z 43 PC: 12f65 | Set date
2018-12-17T22:45:26.671396952Z 64 PC: 13934 | Write file or device (Write 4592 bytes on handle 5)
2018-12-17T22:45:26.68043355Z 62 PC: 138b1 | Close file
2018-12-17T22:45:26.688349563Z 14 PC: 12f65 | Set default drive (Drive = 'B')
2018-12-17T22:45:26.689911937Z 26 PC: 12fb1 | Set disk transfer address
2018-12-17T22:45:26.69174567Z 78 PC: 12fbd | Find first file