Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.5808

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:08.777941435Z 53 PC: 132fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:08.781153546Z 53 PC: 132fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:08.783287593Z 53 PC: 132fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:08.7847328Z 53 PC: 132fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:08.786646189Z 53 PC: 132fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:08.78775899Z 53 PC: 132fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:08.788880176Z 53 PC: 132fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:08.790237901Z 53 PC: 132fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:08.791968414Z 53 PC: 132fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:08.793447981Z 53 PC: 132fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:08.795246246Z 53 PC: 132fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:08.7974424Z 53 PC: 132fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:08.798909193Z 53 PC: 132fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:08.800379832Z 53 PC: 132fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:08.803082474Z 53 PC: 132fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:08.804198184Z 53 PC: 132fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:08.805402733Z 53 PC: 132fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:08.807261874Z 53 PC: 132fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:08.809204472Z 53 PC: 132fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:08.810685747Z 37 PC: 1330f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:08.812805482Z 37 PC: 13317 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:08.814018955Z 37 PC: 1331f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:08.815203578Z 37 PC: 13327 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:08.81808509Z 68 PC: 13e57 | I/O control for devices (Set for = '.PPԹ')
2018-12-17T22:02:08.81948244Z 48 PC: 13b82 | Get DOS version
2018-12-17T22:02:08.820952259Z 48 PC: 13b82 | Get DOS version
2018-12-17T22:02:08.823238545Z 48 PC: 13b82 | Get DOS version
2018-12-17T22:02:08.825045037Z 60 PC: 139c0 | Create or truncate file
2018-12-17T22:02:08.842136361Z 65 PC: 13b09 | Delete file (Filename = '')
2018-12-17T22:02:08.853503157Z 26 PC: 13105 | Set disk transfer address
2018-12-17T22:02:08.854690558Z 78 PC: 13111 | Find first file
2018-12-17T22:02:08.862036973Z 26 PC: 13105 | Set disk transfer address
2018-12-17T22:02:08.864235999Z 78 PC: 13111 | Find first file
2018-12-17T22:02:08.870845406Z 86 PC: 13b4d | Rename file
2018-12-17T22:02:08.88350509Z 53 PC: 13274 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:08.88561329Z 37 PC: 1327d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:08.886830759Z 53 PC: 13274 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:08.88805818Z 37 PC: 1327d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:08.889408276Z 53 PC: 13274 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:08.89217824Z 37 PC: 1327d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:08.893418558Z 53 PC: 13274 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:08.89467874Z 37 PC: 1327d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:08.897303307Z 53 PC: 13274 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:08.898749419Z 37 PC: 1327d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:08.900114548Z 53 PC: 13274 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:08.904860323Z 37 PC: 1327d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:08.906096932Z 53 PC: 13274 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:08.907327984Z 37 PC: 1327d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:08.909829348Z 53 PC: 13274 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:08.91100102Z 37 PC: 1327d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:08.912141703Z 53 PC: 13274 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:08.913865998Z 37 PC: 1327d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:08.915204286Z 53 PC: 13274 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:08.91635502Z 37 PC: 1327d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:08.917927104Z 53 PC: 13274 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:08.91949914Z 37 PC: 1327d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:08.920686355Z 53 PC: 13274 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:08.922694926Z 37 PC: 1327d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:08.923943656Z 53 PC: 13274 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:08.925442676Z 37 PC: 1327d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:08.929446422Z 53 PC: 13274 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:08.931217107Z 37 PC: 1327d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:08.932784592Z 53 PC: 13274 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:08.934547445Z 37 PC: 1327d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:08.944020209Z 53 PC: 13274 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:08.945569832Z 37 PC: 1327d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:08.947337341Z 53 PC: 13274 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:08.949258739Z 37 PC: 1327d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:08.950658956Z 53 PC: 13274 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:08.952433247Z 37 PC: 1327d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:08.954318911Z 53 PC: 13274 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:08.95586907Z 37 PC: 1327d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:08.95799789Z 41 PC: 1322b | Parse filename
2018-12-17T22:02:08.960094166Z 41 PC: 13239 | Parse filename
2018-12-17T22:02:08.961501301Z 75 PC: 13244 | Execute program
2018-12-17T22:02:08.982375117Z 80 PC: 16489 | Set current PSP
2018-12-17T22:02:08.983901482Z 48 PC: 1648e | Get DOS version
2018-12-17T22:02:08.985759481Z 99 PC: 1cc70 | Get DBCS lead byte table pointer
2018-12-17T22:02:08.988695259Z 101 PC: 16514 | Get extended country info
2018-12-17T22:02:08.990924358Z 99 PC: 1651a | Get DBCS lead byte table pointer
2018-12-17T22:02:08.992547552Z 74 PC: 1657c | Reallocate memory
2018-12-17T22:02:08.994330511Z 25 PC: 165b3 | Get default drive
2018-12-17T22:02:08.996265292Z 37 PC: 16073 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:02:08.997822055Z 37 PC: 1607a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:08.999310978Z 37 PC: 16081 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:09.004494359Z 74 PC: 1521c | Reallocate memory
2018-12-17T22:02:09.00626277Z 72 PC: 1525d | Allocate memory
2018-12-17T22:02:09.008152663Z 72 PC: 15295 | Allocate memory
2018-12-17T22:02:09.010637874Z 72 PC: 1529d | Allocate memory