Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.4000.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:18.67835324Z 53 PC: 13316 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:18.679904301Z 53 PC: 13316 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:18.681273454Z 53 PC: 13316 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:18.682370004Z 53 PC: 13316 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:18.683877206Z 53 PC: 13316 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:18.68497913Z 53 PC: 13316 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:18.686149083Z 53 PC: 13316 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:18.687859751Z 53 PC: 13316 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:18.688975906Z 53 PC: 13316 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:18.690021153Z 53 PC: 13316 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:18.691193319Z 53 PC: 13316 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:18.694965865Z 53 PC: 13316 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:18.696110308Z 53 PC: 13316 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:18.697257838Z 53 PC: 13316 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:18.699767515Z 53 PC: 13316 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:18.701239944Z 53 PC: 13316 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:18.703049067Z 53 PC: 13316 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:18.710639685Z 53 PC: 13316 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:18.711957198Z 37 PC: 1332b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:18.713286375Z 37 PC: 13333 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:18.715681978Z 37 PC: 1333b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:18.717652199Z 37 PC: 13343 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:18.719443837Z 68 PC: 1388f | I/O control for devices (Set for = '')
2018-12-17T22:20:18.721927871Z 48 PC: 13d65 | Get DOS version
2018-12-17T22:20:18.723640123Z 48 PC: 13d65 | Get DOS version
2018-12-17T22:20:18.725219805Z 48 PC: 13d65 | Get DOS version
2018-12-17T22:20:18.727624723Z 60 PC: 13bb1 | Create or truncate file
2018-12-17T22:20:18.744081337Z 65 PC: 13cfa | Delete file (Filename = '')
2018-12-17T22:20:18.755481424Z 26 PC: 13135 | Set disk transfer address
2018-12-17T22:20:18.757152434Z 78 PC: 13141 | Find first file
2018-12-17T22:20:18.76134187Z 26 PC: 13135 | Set disk transfer address
2018-12-17T22:20:18.762250791Z 78 PC: 13141 | Find first file
2018-12-17T22:20:18.766605954Z 86 PC: 13d30 | Rename file
2018-12-17T22:20:18.777437945Z 53 PC: 1319c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:18.778377568Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:18.779390739Z 53 PC: 1319c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:18.781802463Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:18.782970789Z 53 PC: 1319c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:18.78391267Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:18.785264018Z 53 PC: 1319c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:18.786126799Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:18.787067274Z 53 PC: 1319c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:18.78840136Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:18.789551984Z 53 PC: 1319c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:18.790468293Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:18.792146484Z 53 PC: 1319c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:18.793385176Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:18.794429372Z 53 PC: 1319c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:18.796095186Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:18.797309015Z 53 PC: 1319c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:18.798328981Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:18.800192994Z 53 PC: 1319c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:18.801177504Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:18.802295117Z 53 PC: 1319c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:18.803864688Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:18.808388838Z 53 PC: 1319c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:18.81191948Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:18.818210658Z 53 PC: 1319c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:18.819278987Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:18.820408132Z 53 PC: 1319c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:18.821878379Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:18.823253078Z 53 PC: 1319c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:18.824393222Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:18.82634539Z 53 PC: 1319c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:18.82821006Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:18.829699785Z 53 PC: 1319c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:18.831286425Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:18.832384591Z 53 PC: 1319c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:18.833374071Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:18.835286617Z 41 PC: 13224 | Parse filename
2018-12-17T22:20:18.836792162Z 41 PC: 13232 | Parse filename
2018-12-17T22:20:18.838120435Z 75 PC: 1323d | Execute program
2018-12-17T22:20:18.873224476Z 80 PC: 16a69 | Set current PSP
2018-12-17T22:20:18.876385159Z 48 PC: 16a6e | Get DOS version
2018-12-17T22:20:18.878235241Z 99 PC: 1d250 | Get DBCS lead byte table pointer
2018-12-17T22:20:18.882559942Z 101 PC: 16af4 | Get extended country info
2018-12-17T22:20:18.884099942Z 99 PC: 16afa | Get DBCS lead byte table pointer
2018-12-17T22:20:18.885257208Z 74 PC: 16b5c | Reallocate memory
2018-12-17T22:20:18.8870917Z 25 PC: 16b93 | Get default drive
2018-12-17T22:20:18.888088683Z 37 PC: 16653 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:20:18.889329466Z 37 PC: 1665a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:18.890532541Z 37 PC: 16661 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:18.895757279Z 74 PC: 157fc | Reallocate memory
2018-12-17T22:20:18.897531666Z 72 PC: 1583d | Allocate memory
2018-12-17T22:20:18.899571932Z 72 PC: 15875 | Allocate memory
2018-12-17T22:20:18.901848921Z 72 PC: 1587d | Allocate memory