Sample viewer

vx.netlux.org/Trojan.DOS.Virri.e

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:06.205772553Z 48 PC: 18d78 | Get DOS version
2018-12-17T22:42:06.20698603Z 74 PC: 18dc8 | Reallocate memory
2018-12-17T22:42:06.209006512Z 48 PC: 18b7c | Get DOS version
2018-12-17T22:42:06.225734432Z 53 PC: 18b84 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:06.227300547Z 37 PC: 18b96 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:06.229088189Z 53 PC: 1b8a2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:42:06.231022325Z 37 PC: 1b8b2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:42:06.232946525Z 53 PC: 1b8b7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:06.234349686Z 37 PC: 1b8c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:06.236640657Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:42:06.238025435Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:42:06.239390196Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:42:06.241414844Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:42:06.242725784Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:42:06.244081872Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:42:06.24603031Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:42:06.259505851Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:42:06.262211836Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:42:06.264473083Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:42:06.265678548Z 53 PC: 195f6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:42:06.267523245Z 37 PC: 19625 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:42:06.269975765Z 37 PC: 19625 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:42:06.271027956Z 37 PC: 19625 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:42:06.272056366Z 37 PC: 19625 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:42:06.273719836Z 37 PC: 19625 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:42:06.275009182Z 37 PC: 19625 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:42:06.276696329Z 37 PC: 19625 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:42:06.278810332Z 37 PC: 19625 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:42:06.280700447Z 37 PC: 1962c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:42:06.282269815Z 37 PC: 19631 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:42:06.284439584Z 68 PC: 18c27 | I/O control for devices (Set for = '�G1��')
2018-12-17T22:42:06.287147779Z 68 PC: 18c27 | I/O control for devices (Set for = '')
2018-12-17T22:42:06.288743312Z 68 PC: 18c27 | I/O control for devices (Set for = 'r��r"�~�B��e ���r �')
2018-12-17T22:42:06.290334022Z 68 PC: 18c27 | I/O control for devices (Set for = ' �')
2018-12-17T22:42:06.292326435Z 68 PC: 18c27 | I/O control for devices (Set for = ' �')
2018-12-17T22:42:06.294122036Z 53 PC: 16234 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:06.29521302Z 53 PC: 16241 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:42:06.297179982Z 53 PC: 1624e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:06.298556714Z 37 PC: 16263 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:06.299873018Z 37 PC: 1626b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:42:06.301455387Z 37 PC: 16273 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:06.306388899Z 53 PC: 167ac | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:06.30779057Z 53 PC: 167b9 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:06.309379899Z 53 PC: 167c8 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:06.311444859Z 37 PC: 167d5 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:06.312741807Z 53 PC: 167dc | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:06.314125973Z 37 PC: 167e9 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:06.31618403Z 53 PC: 167f5 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:42:06.320367516Z 48 PC: 168b7 | Get DOS version
2018-12-17T22:42:06.321773241Z 74 PC: 17f5f | Reallocate memory
2018-12-17T22:42:06.324044446Z 74 PC: 17f5f | Reallocate memory
2018-12-17T22:42:06.325484187Z 68 PC: 161aa | I/O control for devices (Set for = 'sion:5')
2018-12-17T22:42:06.326748073Z 68 PC: 161aa | I/O control for devices (Set for = '')
2018-12-17T22:42:06.328418796Z 51 PC: 161c8 | Get or set Ctrl-Break
2018-12-17T22:42:06.329437854Z 51 PC: 161d4 | Get or set Ctrl-Break
2018-12-17T22:42:06.330562495Z 72 PC: 1874c | Allocate memory
2018-12-17T22:42:06.332512455Z 74 PC: 17f5f | Reallocate memory
2018-12-17T22:42:06.334449902Z 72 PC: 1874c | Allocate memory
2018-12-17T22:42:06.336985941Z 37 PC: 14bcb | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:06.344308949Z 73 PC: 1874c | Release memory
2018-12-17T22:42:06.347253296Z 74 PC: 17f5f | Reallocate memory
2018-12-17T22:42:06.348985015Z 51 PC: 161df | Get or set Ctrl-Break
2018-12-17T22:42:06.350055524Z 37 PC: 16461 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:06.352028314Z 37 PC: 1646b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:42:06.353591231Z 37 PC: 16475 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:06.354892115Z 53 PC: 14f3c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:06.356860316Z 53 PC: 14f49 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:42:06.358443138Z 53 PC: 14f56 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:06.359731791Z 37 PC: 14f71 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:42:06.361630305Z 53 PC: 14f79 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:06.363157108Z 37 PC: 14f86 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:06.364427638Z 53 PC: 14f8d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:06.365780875Z 37 PC: 14f9a | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:06.36762873Z 37 PC: 14fa4 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:06.368859967Z 37 PC: 14faf | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:06.370209922Z 37 PC: 19641 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:42:06.371768244Z 37 PC: 19641 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:42:06.372759083Z 37 PC: 19641 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:42:06.373898909Z 37 PC: 19641 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:42:06.375558173Z 37 PC: 19641 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:42:06.376591206Z 37 PC: 19641 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:42:06.377603465Z 37 PC: 19641 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:42:06.379015802Z 37 PC: 19641 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:42:06.38002426Z 37 PC: 19641 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:42:06.381009329Z 37 PC: 19641 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:42:06.382674088Z 37 PC: 19641 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:42:06.383727082Z 37 PC: 1b8d6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:42:06.384765263Z 37 PC: 18cd8 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:06.387589142Z 41 PC: 18a71 | Parse filename
2018-12-17T22:42:06.389255691Z 41 PC: 18a73 | Parse filename
2018-12-17T22:42:06.390965174Z 41 PC: 18a78 | Parse filename
2018-12-17T22:42:06.392874553Z 75 PC: 18a8e | Execute program
2018-12-17T22:42:06.415105484Z 80 PC: 1ee69 | Set current PSP
2018-12-17T22:42:06.416181825Z 48 PC: 1ee6e | Get DOS version
2018-12-17T22:42:06.41871637Z 99 PC: 25650 | Get DBCS lead byte table pointer
2018-12-17T22:42:06.421429445Z 101 PC: 1eef4 | Get extended country info
2018-12-17T22:42:06.4228608Z 99 PC: 1eefa | Get DBCS lead byte table pointer
2018-12-17T22:42:06.424995014Z 74 PC: 1ef5c | Reallocate memory
2018-12-17T22:42:06.427089131Z 25 PC: 1ef93 | Get default drive
2018-12-17T22:42:06.428135022Z 37 PC: 1ea53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:42:06.429942806Z 37 PC: 1ea5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:06.430995828Z 37 PC: 1ea61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:06.434980521Z 74 PC: 1dbfc | Reallocate memory
2018-12-17T22:42:06.436970281Z 72 PC: 1dc3d | Allocate memory
2018-12-17T22:42:06.438436377Z 72 PC: 1dc75 | Allocate memory
2018-12-17T22:42:06.439878982Z 72 PC: 1dc7d | Allocate memory