Sample viewer

vx.netlux.org/Virus.DOS.Arara.1092

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:11.328064391Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:14:11.335674305Z 41 PC: 94fae | Parse filename
2018-12-17T22:14:11.339989345Z 41 PC: 9502f | Parse filename
2018-12-17T22:14:11.341430359Z 41 PC: 9504c | Parse filename
2018-12-17T22:14:11.344511238Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:14:11.347110261Z 71 PC: 986f3 | Get current directory
2018-12-17T22:14:11.350199233Z 78 PC: 986fe | Find first file
2018-12-17T22:14:11.360099646Z 71 PC: 986f3 | Get current directory
2018-12-17T22:14:11.363268201Z 78 PC: 986fe | Find first file
2018-12-17T22:14:11.373702391Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T22:14:11.378362136Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:14:11.379789392Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:11.38139084Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:11.382776044Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.384497879Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.386432193Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.388299202Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.390234646Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.392805793Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.395088967Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.396835601Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.399132651Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.401074523Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.402591964Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.404654586Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.406350183Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.407985024Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.411476139Z 62 PC: 122ab | Close file
2018-12-17T22:14:11.413318783Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:14:11.414690231Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:14:11.417029804Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:14:11.422409245Z 25 PC: 94e62 | Get default drive
2018-12-17T22:14:11.424185404Z 71 PC: 970dd | Get current directory
2018-12-17T22:14:11.428391995Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:14:11.433253571Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:14:11.435638429Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:14:11.438236718Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:14:11.440740814Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:14:26.371222198Z 0 PC: 0 | Program terminate
2018-12-17T22:14:27.726644804Z 0 PC: 0 | Program terminate
2018-12-17T22:14:27.829568236Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:14:27.835824099Z 41 PC: 94fae | Parse filename
2018-12-17T22:14:27.837809902Z 41 PC: 9502f | Parse filename
2018-12-17T22:14:27.839458974Z 41 PC: 9504c | Parse filename
2018-12-17T22:14:27.84394782Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:14:27.845754212Z 71 PC: 986f3 | Get current directory
2018-12-17T22:14:27.853146527Z 78 PC: 986fe | Find first file
2018-12-17T22:14:27.866966948Z 71 PC: 9856c | Get current directory
2018-12-17T22:14:27.870173144Z 73 PC: 97c09 | Release memory
2018-12-17T22:14:27.87156775Z 75 PC: 11821 | Execute program
2018-12-17T22:14:27.885559381Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:14:27.891125308Z 76 PC: 12a4b | Terminate with return code (Return code = '36')