Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.6000.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:19.477761654Z 53 PC: 1337a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:19.479985366Z 53 PC: 1337a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:10:19.481572144Z 53 PC: 1337a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:10:19.482752781Z 53 PC: 1337a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:19.484135476Z 53 PC: 1337a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:19.486389432Z 53 PC: 1337a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:19.488009978Z 53 PC: 1337a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:10:19.489455437Z 53 PC: 1337a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:10:19.491236079Z 53 PC: 1337a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:10:19.492340782Z 53 PC: 1337a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:10:19.493424959Z 53 PC: 1337a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:10:19.495469705Z 53 PC: 1337a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:10:19.496674104Z 53 PC: 1337a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:10:19.497844667Z 53 PC: 1337a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:10:19.500072496Z 53 PC: 1337a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:10:19.501844939Z 53 PC: 1337a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:10:19.503597644Z 53 PC: 1337a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:10:19.50600869Z 53 PC: 1337a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:10:19.508346899Z 53 PC: 1337a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:10:19.510070829Z 37 PC: 1338f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:19.511905885Z 37 PC: 13397 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:19.513335139Z 37 PC: 1339f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:19.514941602Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:10:19.516748725Z 68 PC: 13ed7 | I/O control for devices (Set for = 'r U')
2018-12-17T22:10:19.518700688Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:10:19.520072267Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:10:19.521381654Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:10:19.524529998Z 60 PC: 13a40 | Create or truncate file
2018-12-17T22:10:19.543978256Z 65 PC: 13b89 | Delete file (Filename = '')
2018-12-17T22:10:19.5576776Z 26 PC: 13185 | Set disk transfer address
2018-12-17T22:10:19.560478252Z 78 PC: 13191 | Find first file
2018-12-17T22:10:19.567164969Z 26 PC: 13185 | Set disk transfer address
2018-12-17T22:10:19.568401914Z 78 PC: 13191 | Find first file
2018-12-17T22:10:19.575873259Z 86 PC: 13bcd | Rename file
2018-12-17T22:10:19.589944547Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:19.591191077Z 37 PC: 132fd | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:19.59373786Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:10:19.595446731Z 37 PC: 132fd | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:10:19.597006507Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:10:19.599640272Z 37 PC: 132fd | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:10:19.601185253Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:19.602713454Z 37 PC: 132fd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:19.604915917Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:19.606577813Z 37 PC: 132fd | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:19.607682882Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:19.608998399Z 37 PC: 132fd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:19.610576799Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:10:19.611642564Z 37 PC: 132fd | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:10:19.612745709Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:10:19.614523172Z 37 PC: 132fd | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:10:19.615558756Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:10:19.616651718Z 37 PC: 132fd | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:10:19.618895808Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:10:19.620262285Z 37 PC: 132fd | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:10:19.621316425Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:10:19.6307224Z 37 PC: 132fd | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:10:19.631831416Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:10:19.632930073Z 37 PC: 132fd | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:10:19.634858943Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:10:19.635921991Z 37 PC: 132fd | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:10:19.637138961Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:10:19.639179386Z 37 PC: 132fd | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:10:19.640311887Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:10:19.641503716Z 37 PC: 132fd | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:10:19.643380574Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:10:19.645119701Z 37 PC: 132fd | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:10:19.646422407Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:10:19.648695445Z 37 PC: 132fd | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:10:19.650007046Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:10:19.65117048Z 37 PC: 132fd | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:10:19.653981269Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:10:19.655098301Z 37 PC: 132fd | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:10:19.656773198Z 41 PC: 132ab | Parse filename
2018-12-17T22:10:19.659431078Z 41 PC: 132b9 | Parse filename
2018-12-17T22:10:19.660892193Z 75 PC: 132c4 | Execute program
2018-12-17T22:10:19.683434503Z 80 PC: 16449 | Set current PSP
2018-12-17T22:10:19.685094546Z 48 PC: 1644e | Get DOS version
2018-12-17T22:10:19.687092085Z 99 PC: 1cc30 | Get DBCS lead byte table pointer
2018-12-17T22:10:19.689983021Z 101 PC: 164d4 | Get extended country info
2018-12-17T22:10:19.692123284Z 99 PC: 164da | Get DBCS lead byte table pointer
2018-12-17T22:10:19.693786912Z 74 PC: 1653c | Reallocate memory
2018-12-17T22:10:19.69543912Z 25 PC: 16573 | Get default drive
2018-12-17T22:10:19.696951577Z 37 PC: 16033 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:10:19.698884751Z 37 PC: 1603a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:19.700029937Z 37 PC: 16041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:19.704398724Z 74 PC: 151dc | Reallocate memory
2018-12-17T22:10:19.706501266Z 72 PC: 1521d | Allocate memory
2018-12-17T22:10:19.708269466Z 72 PC: 15255 | Allocate memory
2018-12-17T22:10:19.709985259Z 72 PC: 1525d | Allocate memory