Sample viewer

vx.netlux.org/Virus.DOS.HLLO.3520.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:23.718278976Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:23.720125283Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:23.722533366Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:23.724749678Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:23.726206785Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:23.72959028Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:23.735398378Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:23.737253853Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:23.740103605Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:23.742133097Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:23.744026543Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:23.746561314Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:23.748222714Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:23.749833078Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:23.751791216Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:23.753913212Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:23.756156375Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:23.757963669Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:23.759851234Z 53 PC: 12d8a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:23.761718631Z 37 PC: 12d9f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:23.76327287Z 37 PC: 12da7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:23.764486098Z 37 PC: 12daf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:23.765751525Z 37 PC: 12db7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:23.769663763Z 68 PC: 13659 | I/O control for devices (Set for = '')
2018-12-17T22:46:23.771842475Z 26 PC: 12b95 | Set disk transfer address
2018-12-17T22:46:23.773189094Z 78 PC: 12ba1 | Find first file
2018-12-17T22:46:23.780495336Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:23.782252196Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:23.783833897Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:23.787140988Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:23.789340979Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:23.790779892Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:23.793112033Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:23.795055663Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:23.796616073Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:23.79823311Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:23.803872271Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:23.805263704Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:23.807618187Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:23.809426764Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:23.810720263Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:23.811947237Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:23.813627182Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:23.814927294Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:23.816044653Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:23.81956778Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:23.820766531Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:23.822063237Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:23.824529028Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:23.82581887Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:23.827391434Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:23.830708704Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:23.840647059Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:23.842465094Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:23.844628678Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:23.85880379Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:23.860298337Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:23.86183322Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:23.863905071Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:23.865478346Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:23.867041241Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:23.869610226Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:23.871133167Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:23.872705881Z 37 PC: 12d0d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:23.875691698Z 48 PC: 13384 | Get DOS version
2018-12-17T22:46:23.877730868Z 41 PC: 12cbb | Parse filename
2018-12-17T22:46:23.880402816Z 41 PC: 12cc9 | Parse filename
2018-12-17T22:46:23.883303494Z 75 PC: 12cd4 | Execute program
2018-12-17T22:46:23.911092566Z 80 PC: 158e9 | Set current PSP
2018-12-17T22:46:23.912318789Z 48 PC: 158ee | Get DOS version
2018-12-17T22:46:23.91512014Z 99 PC: 1c0d0 | Get DBCS lead byte table pointer
2018-12-17T22:46:23.91881539Z 101 PC: 15974 | Get extended country info
2018-12-17T22:46:23.920407531Z 99 PC: 1597a | Get DBCS lead byte table pointer
2018-12-17T22:46:23.921776371Z 74 PC: 159dc | Reallocate memory
2018-12-17T22:46:23.92377208Z 25 PC: 15a13 | Get default drive
2018-12-17T22:46:23.92533213Z 37 PC: 154d3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:46:23.927007266Z 37 PC: 154da | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:23.929335028Z 37 PC: 154e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:23.93438396Z 74 PC: 1467c | Reallocate memory
2018-12-17T22:46:23.936411408Z 72 PC: 146bd | Allocate memory
2018-12-17T22:46:23.939253667Z 72 PC: 146f5 | Allocate memory
2018-12-17T22:46:23.941302815Z 72 PC: 146fd | Allocate memory