Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Rider.6016

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:17:18.941689289Z 53 PC: 1338a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:18.944371524Z 53 PC: 1338a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:17:18.945781974Z 53 PC: 1338a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:17:18.947597812Z 53 PC: 1338a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:18.950256842Z 53 PC: 1338a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:18.951443423Z 53 PC: 1338a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:18.953470278Z 53 PC: 1338a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:17:18.955464915Z 53 PC: 1338a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:17:18.957972247Z 53 PC: 1338a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:17:18.960027823Z 53 PC: 1338a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:17:18.962010335Z 53 PC: 1338a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:17:18.965709481Z 53 PC: 1338a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:17:18.966843523Z 53 PC: 1338a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:17:18.968044176Z 53 PC: 1338a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:17:18.971029931Z 53 PC: 1338a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:17:18.972484066Z 53 PC: 1338a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:17:18.97403121Z 53 PC: 1338a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:17:18.976166452Z 53 PC: 1338a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:18.977492451Z 53 PC: 1338a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:17:18.978668331Z 37 PC: 1339f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:18.980396901Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:18.981484021Z 37 PC: 133af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:18.982313001Z 37 PC: 133b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:18.987254807Z 68 PC: 13ee7 | I/O control for devices (Set for = 'Q��&��"�"&��:�u��3��1��3��5��A��I��K��>C�')
2018-12-17T22:17:18.988774615Z 48 PC: 13c12 | Get DOS version
2018-12-17T22:17:18.990153311Z 48 PC: 13c12 | Get DOS version
2018-12-17T22:17:19.005051565Z 48 PC: 13c12 | Get DOS version
2018-12-17T22:17:19.006822008Z 60 PC: 13a50 | Create or truncate file
2018-12-17T22:17:19.023814031Z 65 PC: 13b99 | Delete file (Filename = '�')
2018-12-17T22:17:19.037747353Z 26 PC: 13195 | Set disk transfer address
2018-12-17T22:17:19.039190646Z 78 PC: 131a1 | Find first file
2018-12-17T22:17:19.04569254Z 26 PC: 13195 | Set disk transfer address
2018-12-17T22:17:19.047313463Z 78 PC: 131a1 | Find first file
2018-12-17T22:17:19.053628645Z 86 PC: 13bdd | Rename file
2018-12-17T22:17:19.068039389Z 53 PC: 13304 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:19.07088038Z 37 PC: 1330d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:17:19.07202711Z 53 PC: 13304 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:17:19.073156963Z 37 PC: 1330d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:17:19.08678329Z 53 PC: 13304 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:17:19.088615852Z 37 PC: 1330d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:17:19.089678761Z 53 PC: 13304 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:19.091095854Z 37 PC: 1330d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:19.093090598Z 53 PC: 13304 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:19.094264277Z 37 PC: 1330d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:19.095394438Z 53 PC: 13304 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:19.097284393Z 37 PC: 1330d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:19.098603449Z 53 PC: 13304 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:17:19.099964469Z 37 PC: 1330d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:17:19.101767179Z 53 PC: 13304 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:17:19.103211823Z 37 PC: 1330d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:17:19.10458722Z 53 PC: 13304 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:17:19.106787438Z 37 PC: 1330d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:17:19.108244875Z 53 PC: 13304 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:17:19.109605497Z 37 PC: 1330d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:17:19.111817978Z 53 PC: 13304 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:17:19.113309392Z 37 PC: 1330d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:17:19.114478285Z 53 PC: 13304 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:17:19.116822367Z 37 PC: 1330d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:17:19.118017182Z 53 PC: 13304 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:17:19.119175818Z 37 PC: 1330d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:17:19.121789249Z 53 PC: 13304 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:17:19.123280189Z 37 PC: 1330d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:17:19.1252405Z 53 PC: 13304 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:17:19.127607858Z 37 PC: 1330d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:17:19.129031378Z 53 PC: 13304 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:17:19.130522422Z 37 PC: 1330d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:17:19.134557655Z 53 PC: 13304 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:17:19.13601264Z 37 PC: 1330d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:17:19.137373868Z 53 PC: 13304 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:19.139658498Z 37 PC: 1330d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:17:19.141504915Z 53 PC: 13304 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:17:19.142876916Z 37 PC: 1330d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:17:19.14560529Z 41 PC: 132bb | Parse filename
2018-12-17T22:17:19.147173655Z 41 PC: 132c9 | Parse filename
2018-12-17T22:17:19.148673585Z 75 PC: 132d4 | Execute program
2018-12-17T22:17:19.171005768Z 80 PC: 16449 | Set current PSP
2018-12-17T22:17:19.17214646Z 48 PC: 1644e | Get DOS version
2018-12-17T22:17:19.1739127Z 99 PC: 1cc30 | Get DBCS lead byte table pointer
2018-12-17T22:17:19.177397572Z 101 PC: 164d4 | Get extended country info
2018-12-17T22:17:19.179156942Z 99 PC: 164da | Get DBCS lead byte table pointer
2018-12-17T22:17:19.180643136Z 74 PC: 1653c | Reallocate memory
2018-12-17T22:17:19.18254163Z 25 PC: 16573 | Get default drive
2018-12-17T22:17:19.184102841Z 37 PC: 16033 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:17:19.185424597Z 37 PC: 1603a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:19.186934094Z 37 PC: 16041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:19.191988334Z 74 PC: 151dc | Reallocate memory
2018-12-17T22:17:19.193599993Z 72 PC: 1521d | Allocate memory
2018-12-17T22:17:19.195355572Z 72 PC: 15255 | Allocate memory
2018-12-17T22:17:19.198013302Z 72 PC: 1525d | Allocate memory