Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Apocalipse.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:11.677912993Z 48 PC: 152e4 | Get DOS version
2018-12-17T22:47:11.679877633Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.681425494Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.683016504Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.685769327Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.687426406Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.689068611Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.690991906Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.693338595Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.694897651Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.696481907Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.699308104Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.700856651Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.702415875Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.704950523Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.706533738Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.708143047Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.710693797Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.71272435Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.71466303Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.717073423Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.719623882Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.721661513Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.72340125Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.725542045Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.727550964Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.72960269Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.732395947Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.734646138Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.736780375Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.741898452Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.743157468Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.744352216Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.747441476Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.74952522Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.752066142Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.75483396Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.757066313Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.758527725Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.761006122Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.76219845Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.763400057Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.765536752Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.767463777Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.769202998Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.771439732Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.772733315Z 48 PC: 154bb | Get DOS version
2018-12-17T22:47:11.77381509Z 48 PC: 154c8 | Get DOS version
2018-12-17T22:47:11.77606885Z 48 PC: 154df | Get DOS version
2018-12-17T22:47:11.777323066Z 53 PC: 154fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.778567673Z 53 PC: 154ff | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:11.780556028Z 61 PC: 15534 | Open file (Filename = 'EMP=C:\WINDOWS\TEMP ')