Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.4094

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:02.879182505Z 53 PC: 13382 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:02.881152591Z 53 PC: 13382 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:02.882387833Z 53 PC: 13382 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:02.883499422Z 53 PC: 13382 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:02.885586709Z 53 PC: 13382 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:02.88721704Z 53 PC: 13382 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:02.888400846Z 53 PC: 13382 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:02.890446074Z 53 PC: 13382 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:02.892112987Z 53 PC: 13382 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:02.893144608Z 53 PC: 13382 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:02.894133567Z 53 PC: 13382 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:02.910303852Z 53 PC: 13382 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:02.911413079Z 53 PC: 13382 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:02.91250096Z 53 PC: 13382 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:02.914570806Z 53 PC: 13382 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:02.916428553Z 53 PC: 13382 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:02.91781655Z 53 PC: 13382 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:02.920869314Z 53 PC: 13382 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:02.922788784Z 53 PC: 13382 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:02.924744906Z 37 PC: 13397 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:02.930735796Z 37 PC: 1339f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:02.931828421Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:02.932838668Z 37 PC: 133af | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:02.934643633Z 68 PC: 1371f | I/O control for devices (Set for = '')
2018-12-17T22:50:02.936313466Z 48 PC: 13e0a | Get DOS version
2018-12-17T22:50:02.93736067Z 48 PC: 13e0a | Get DOS version
2018-12-17T22:50:02.938850955Z 48 PC: 13e0a | Get DOS version
2018-12-17T22:50:02.940953218Z 60 PC: 13c56 | Create or truncate file
2018-12-17T22:50:02.958287849Z 65 PC: 13d9f | Delete file (Filename = '�')
2018-12-17T22:50:02.970972194Z 26 PC: 13195 | Set disk transfer address
2018-12-17T22:50:02.971929179Z 78 PC: 131a1 | Find first file
2018-12-17T22:50:02.97809608Z 26 PC: 13195 | Set disk transfer address
2018-12-17T22:50:02.97941811Z 78 PC: 131a1 | Find first file
2018-12-17T22:50:02.98555202Z 86 PC: 13dd5 | Rename file
2018-12-17T22:50:02.999480741Z 53 PC: 131fc | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:03.001576729Z 37 PC: 13205 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:03.003053632Z 53 PC: 131fc | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:03.004417566Z 37 PC: 13205 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:50:03.005884996Z 53 PC: 131fc | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:03.007785623Z 37 PC: 13205 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:50:03.008937543Z 53 PC: 131fc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:03.010138425Z 37 PC: 13205 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:03.011661094Z 53 PC: 131fc | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:03.012876569Z 37 PC: 13205 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:03.014079016Z 53 PC: 131fc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:03.015612479Z 37 PC: 13205 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:03.016726798Z 53 PC: 131fc | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:03.017853892Z 37 PC: 13205 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:50:03.019428172Z 53 PC: 131fc | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:03.020519501Z 37 PC: 13205 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:50:03.022881766Z 53 PC: 131fc | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:03.024178206Z 37 PC: 13205 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:50:03.025508109Z 53 PC: 131fc | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:03.026533864Z 37 PC: 13205 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:50:03.02791283Z 53 PC: 131fc | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:03.028944272Z 37 PC: 13205 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:50:03.030271896Z 53 PC: 131fc | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:03.031989356Z 37 PC: 13205 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:50:03.033168015Z 53 PC: 131fc | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:03.035300481Z 37 PC: 13205 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:50:03.036906721Z 53 PC: 131fc | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:03.038077693Z 37 PC: 13205 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:50:03.039063091Z 53 PC: 131fc | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:03.041051983Z 37 PC: 13205 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:50:03.04208376Z 53 PC: 131fc | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:03.043158059Z 37 PC: 13205 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:50:03.044917126Z 53 PC: 131fc | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:03.046110529Z 37 PC: 13205 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:50:03.047188629Z 53 PC: 131fc | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:03.049491744Z 37 PC: 13205 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:50:03.050548842Z 53 PC: 131fc | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:03.051832207Z 37 PC: 13205 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:50:03.0543803Z 41 PC: 13285 | Parse filename
2018-12-17T22:50:03.055714881Z 41 PC: 13293 | Parse filename
2018-12-17T22:50:03.057188287Z 75 PC: 1329e | Execute program
2018-12-17T22:50:03.090433544Z 80 PC: 16689 | Set current PSP
2018-12-17T22:50:03.091270502Z 48 PC: 1668e | Get DOS version
2018-12-17T22:50:03.093048518Z 99 PC: 1ce70 | Get DBCS lead byte table pointer
2018-12-17T22:50:03.096778589Z 101 PC: 16714 | Get extended country info
2018-12-17T22:50:03.098273718Z 99 PC: 1671a | Get DBCS lead byte table pointer
2018-12-17T22:50:03.099616173Z 74 PC: 1677c | Reallocate memory
2018-12-17T22:50:03.101867215Z 25 PC: 167b3 | Get default drive
2018-12-17T22:50:03.103786589Z 37 PC: 16273 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:50:03.105121696Z 37 PC: 1627a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:50:03.107126832Z 37 PC: 16281 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:50:03.111507724Z 74 PC: 1541c | Reallocate memory
2018-12-17T22:50:03.113083842Z 72 PC: 1545d | Allocate memory
2018-12-17T22:50:03.115639562Z 72 PC: 15495 | Allocate memory
2018-12-17T22:50:03.117330253Z 72 PC: 1549d | Allocate memory