Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.6016

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:04.754410906Z 53 PC: 1338a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:04.756510475Z 53 PC: 1338a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:04.758886032Z 53 PC: 1338a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:04.760488626Z 53 PC: 1338a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:04.76206498Z 53 PC: 1338a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:04.764764416Z 53 PC: 1338a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:04.766747496Z 53 PC: 1338a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:04.768444507Z 53 PC: 1338a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:04.770901838Z 53 PC: 1338a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:04.773193277Z 53 PC: 1338a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:04.774976901Z 53 PC: 1338a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:04.777952306Z 53 PC: 1338a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:04.779788971Z 53 PC: 1338a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:04.781443472Z 53 PC: 1338a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:04.784413788Z 53 PC: 1338a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:04.786250882Z 53 PC: 1338a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:04.78789266Z 53 PC: 1338a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:04.789574954Z 53 PC: 1338a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:04.792425033Z 53 PC: 1338a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:12:04.794159946Z 37 PC: 1339f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:04.795757049Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:04.798401412Z 37 PC: 133af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:04.800279193Z 37 PC: 133b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:04.802561024Z 68 PC: 13eec | I/O control for devices (Set for = 'Q��&��"�"&��:�u��3��1��3��5��A��I��K��>C�')
2018-12-17T23:12:04.806044525Z 48 PC: 13c12 | Get DOS version
2018-12-17T23:12:04.808180421Z 48 PC: 13c12 | Get DOS version
2018-12-17T23:12:04.810157209Z 48 PC: 13c12 | Get DOS version
2018-12-17T23:12:04.813379459Z 60 PC: 13a50 | Create or truncate file
2018-12-17T23:12:04.832628376Z 65 PC: 13b99 | Delete file (Filename = '�')
2018-12-17T23:12:04.844985514Z 26 PC: 13195 | Set disk transfer address
2018-12-17T23:12:04.847514821Z 78 PC: 131a1 | Find first file
2018-12-17T23:12:04.855850065Z 26 PC: 13195 | Set disk transfer address
2018-12-17T23:12:04.85765555Z 78 PC: 131a1 | Find first file
2018-12-17T23:12:04.865593167Z 86 PC: 13bdd | Rename file
2018-12-17T23:12:04.879565332Z 53 PC: 13304 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:04.881032992Z 37 PC: 1330d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:12:04.882732308Z 53 PC: 13304 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:04.88640771Z 37 PC: 1330d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:12:04.888018208Z 53 PC: 13304 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:04.889673912Z 37 PC: 1330d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:12:04.8919275Z 53 PC: 13304 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:04.893438511Z 37 PC: 1330d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:04.894966404Z 53 PC: 13304 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:04.897264196Z 37 PC: 1330d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:04.898908508Z 53 PC: 13304 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:04.900455427Z 37 PC: 1330d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:04.90243511Z 53 PC: 13304 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:04.90457283Z 37 PC: 1330d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:12:04.906280582Z 53 PC: 13304 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:04.908103169Z 37 PC: 1330d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:12:04.909586578Z 53 PC: 13304 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:04.910872657Z 37 PC: 1330d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:12:04.912136814Z 53 PC: 13304 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:04.913804259Z 37 PC: 1330d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:12:04.915034573Z 53 PC: 13304 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:04.91630354Z 37 PC: 1330d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:12:04.918442102Z 53 PC: 13304 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:04.919910463Z 37 PC: 1330d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:12:04.922144824Z 53 PC: 13304 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:04.924511214Z 37 PC: 1330d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:12:04.925956322Z 53 PC: 13304 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:04.927379909Z 37 PC: 1330d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:12:04.929858721Z 53 PC: 13304 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:04.931374942Z 37 PC: 1330d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:12:04.932829367Z 53 PC: 13304 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:04.935254838Z 37 PC: 1330d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:12:04.93681436Z 53 PC: 13304 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:04.938491645Z 37 PC: 1330d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:12:04.940391277Z 53 PC: 13304 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:04.942151237Z 37 PC: 1330d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:12:04.943501636Z 53 PC: 13304 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:12:04.945593921Z 37 PC: 1330d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:12:04.947913432Z 41 PC: 132bb | Parse filename
2018-12-17T23:12:04.949639358Z 41 PC: 132c9 | Parse filename
2018-12-17T23:12:04.951575259Z 75 PC: 132d4 | Execute program
2018-12-17T23:12:04.97627664Z 80 PC: 16449 | Set current PSP
2018-12-17T23:12:04.977591914Z 48 PC: 1644e | Get DOS version
2018-12-17T23:12:04.979616691Z 99 PC: 1cc30 | Get DBCS lead byte table pointer
2018-12-17T23:12:04.983611523Z 101 PC: 164d4 | Get extended country info
2018-12-17T23:12:04.985895288Z 99 PC: 164da | Get DBCS lead byte table pointer
2018-12-17T23:12:04.987659015Z 74 PC: 1653c | Reallocate memory
2018-12-17T23:12:04.990308708Z 25 PC: 16573 | Get default drive
2018-12-17T23:12:04.992258915Z 37 PC: 16033 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:12:04.993877188Z 37 PC: 1603a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:04.995442231Z 37 PC: 16041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:05.001336636Z 74 PC: 151dc | Reallocate memory
2018-12-17T23:12:05.003249283Z 72 PC: 1521d | Allocate memory
2018-12-17T23:12:05.006098381Z 72 PC: 15255 | Allocate memory
2018-12-17T23:12:05.009322384Z 72 PC: 1525d | Allocate memory