Sample viewer

vx.netlux.org/Virus.DOS.HLLO.5151

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:48.260864432Z 53 PC: 13126 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:48.262691508Z 53 PC: 13126 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:48.264063261Z 53 PC: 13126 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:48.265210541Z 53 PC: 13126 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:48.267296037Z 53 PC: 13126 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:48.27772704Z 53 PC: 13126 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:48.278758538Z 53 PC: 13126 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:48.28044709Z 53 PC: 13126 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:48.281357673Z 53 PC: 13126 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:48.282229073Z 53 PC: 13126 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:48.283645726Z 53 PC: 13126 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:48.284579123Z 53 PC: 13126 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:48.285540222Z 53 PC: 13126 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:48.286893985Z 53 PC: 13126 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:48.288170062Z 53 PC: 13126 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:48.289052548Z 53 PC: 13126 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:48.290150408Z 53 PC: 13126 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:48.297053978Z 53 PC: 13126 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:48.298643905Z 37 PC: 1313b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:48.300097251Z 37 PC: 13143 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:48.303094051Z 37 PC: 1314b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:48.304208742Z 37 PC: 13153 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:48.305847839Z 68 PC: 136b7 | I/O control for devices (Set for = '')
2018-12-17T21:57:48.308342271Z 51 PC: 12eed | Get or set Ctrl-Break
2018-12-17T21:57:48.310010967Z 48 PC: 13b27 | Get DOS version
2018-12-17T21:57:48.312541668Z 14 PC: 13c0d | Set default drive (Drive = 'C')
2018-12-17T21:57:48.314671631Z 25 PC: 13c11 | Get default drive
2018-12-17T21:57:48.315810014Z 59 PC: 13c7b | Change current directory
2018-12-17T21:57:48.319453172Z 25 PC: 13bb4 | Get default drive
2018-12-17T21:57:48.321549411Z 71 PC: 13bc7 | Get current directory
2018-12-17T21:57:48.324546438Z 26 PC: 12f9e | Set disk transfer address
2018-12-17T21:57:48.325975147Z 78 PC: 12faa | Find first file
2018-12-17T21:57:48.332710467Z 26 PC: 12f9e | Set disk transfer address
2018-12-17T21:57:48.333966349Z 78 PC: 12faa | Find first file
2018-12-17T21:57:48.339755381Z 59 PC: 13c7b | Change current directory
2018-12-17T21:57:48.346727498Z 26 PC: 12f9e | Set disk transfer address
2018-12-17T21:57:48.348525998Z 78 PC: 12faa | Find first file
2018-12-17T21:57:48.358362714Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.697374572Z 61 PC: 139d9 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T21:57:48.704215574Z 61 PC: 139d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:48.710750566Z 63 PC: 13aac | Read file or device (Read 5151 bytes on handle 6)
2018-12-17T21:57:48.718620262Z 64 PC: 13aac | Write file or device (Write 5151 bytes on handle 5)
2018-12-17T21:57:48.726661908Z 87 PC: 12f6e | Get or set file date and time
2018-12-17T21:57:48.728210007Z 62 PC: 13a29 | Close file
2018-12-17T21:57:48.730191415Z 62 PC: 13a29 | Close file
2018-12-17T21:57:48.736726182Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.74669451Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:48.748160431Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:48.751486015Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.760922962Z 61 PC: 139d9 | Open file (Filename = 'CHKDSK.EXE')
2018-12-17T21:57:48.768105606Z 61 PC: 139d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:48.774815482Z 63 PC: 13aac | Read file or device (Read 5151 bytes on handle 6)
2018-12-17T21:57:48.783577897Z 64 PC: 13aac | Write file or device (Write 5151 bytes on handle 5)
2018-12-17T21:57:48.792103993Z 87 PC: 12f6e | Get or set file date and time
2018-12-17T21:57:48.793747631Z 62 PC: 13a29 | Close file
2018-12-17T21:57:48.795550983Z 62 PC: 13a29 | Close file
2018-12-17T21:57:48.803621465Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.815327134Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:48.817538364Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:48.822194609Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.841622059Z 61 PC: 139d9 | Open file (Filename = 'DEBUG.EXE')
2018-12-17T21:57:48.849084021Z 61 PC: 139d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:48.85640574Z 63 PC: 13aac | Read file or device (Read 5151 bytes on handle 6)
2018-12-17T21:57:48.865207976Z 64 PC: 13aac | Write file or device (Write 5151 bytes on handle 5)
2018-12-17T21:57:48.877723281Z 87 PC: 12f6e | Get or set file date and time
2018-12-17T21:57:48.87957856Z 62 PC: 13a29 | Close file
2018-12-17T21:57:48.88242482Z 62 PC: 13a29 | Close file
2018-12-17T21:57:48.936564287Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.967726665Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:48.970133971Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:48.974157014Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:48.99384171Z 61 PC: 139d9 | Open file (Filename = 'EXPAND.EXE')
2018-12-17T21:57:49.001433369Z 61 PC: 139d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:49.009163374Z 63 PC: 13aac | Read file or device (Read 5151 bytes on handle 6)
2018-12-17T21:57:49.016929205Z 64 PC: 13aac | Write file or device (Write 5151 bytes on handle 5)
2018-12-17T21:57:49.041719797Z 87 PC: 12f6e | Get or set file date and time
2018-12-17T21:57:49.044387562Z 62 PC: 13a29 | Close file
2018-12-17T21:57:49.046175072Z 62 PC: 13a29 | Close file
2018-12-17T21:57:49.126353862Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:49.176938737Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:49.178410879Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:49.182323439Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:49.227666742Z 61 PC: 139d9 | Open file (Filename = 'FDISK.EXE')
2018-12-17T21:57:49.233553226Z 61 PC: 139d9 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:57:49.238644269Z 63 PC: 13aac | Read file or device (Read 5151 bytes on handle 6)
2018-12-17T21:57:49.244254983Z 64 PC: 13aac | Write file or device (Write 5151 bytes on handle 5)
2018-12-17T21:57:49.300056403Z 87 PC: 12f6e | Get or set file date and time
2018-12-17T21:57:49.301957249Z 62 PC: 13a29 | Close file
2018-12-17T21:57:49.304710447Z 62 PC: 13a29 | Close file
2018-12-17T21:57:49.379063128Z 67 PC: 12f27 | Get or set file attributes
2018-12-17T21:57:49.450152691Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:49.45141818Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:49.454825907Z 26 PC: 12f9e | Set disk transfer address
2018-12-17T21:57:49.456937694Z 78 PC: 12faa | Find first file
2018-12-17T21:57:49.462806358Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:49.463877558Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:49.467999009Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:49.46901468Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:49.474994319Z 25 PC: 13bb4 | Get default drive
2018-12-17T21:57:49.476509616Z 71 PC: 13bc7 | Get current directory
2018-12-17T21:57:49.479087341Z 59 PC: 13c7b | Change current directory
2018-12-17T21:57:49.482889421Z 26 PC: 12fc2 | Set disk transfer address
2018-12-17T21:57:49.484928208Z 79 PC: 12fc7 | Find next file
2018-12-17T21:57:49.487831149Z 59 PC: 13c7b | Change current directory
2018-12-17T21:57:49.496729994Z 14 PC: 13c0d | Set default drive (Drive = 'A')
2018-12-17T21:57:49.498582384Z 25 PC: 13c11 | Get default drive
2018-12-17T21:57:49.500722592Z 64 PC: 137ba | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:57:49.502515085Z 37 PC: 13235 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:49.504593049Z 37 PC: 13235 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:49.505656187Z 37 PC: 13235 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:49.506753589Z 37 PC: 13235 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:49.508827877Z 37 PC: 13235 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:49.510057639Z 37 PC: 13235 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:49.511129989Z 37 PC: 13235 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:49.512476904Z 37 PC: 13235 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:49.51447425Z 37 PC: 13235 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:49.515829154Z 37 PC: 13235 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:49.517306007Z 37 PC: 13235 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:49.51960474Z 37 PC: 13235 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:49.520902356Z 37 PC: 13235 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:49.522376237Z 37 PC: 13235 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:49.525226942Z 37 PC: 13235 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:49.526604776Z 37 PC: 13235 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:49.528125361Z 37 PC: 13235 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:49.529916936Z 37 PC: 13235 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:49.531225678Z 76 PC: 13274 | Terminate with return code (Return code = '0')