Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.6000.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:44.086703829Z 53 PC: 1337a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:44.088533104Z 53 PC: 1337a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:44.09182131Z 53 PC: 1337a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:44.093589011Z 53 PC: 1337a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:44.095723316Z 53 PC: 1337a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:44.09809153Z 53 PC: 1337a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:44.099820247Z 53 PC: 1337a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:44.101533826Z 53 PC: 1337a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:44.10442389Z 53 PC: 1337a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:44.10611474Z 53 PC: 1337a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:44.107767192Z 53 PC: 1337a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:44.109813275Z 53 PC: 1337a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:44.111249733Z 53 PC: 1337a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:44.112516402Z 53 PC: 1337a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:44.114375535Z 53 PC: 1337a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:44.116247192Z 53 PC: 1337a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:44.117888284Z 53 PC: 1337a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:44.119542956Z 53 PC: 1337a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:44.121073472Z 53 PC: 1337a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:44.122286496Z 37 PC: 1338f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:44.123420697Z 37 PC: 13397 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:44.124882701Z 37 PC: 1339f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:44.125968874Z 37 PC: 133a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:44.127496477Z 68 PC: 13ed7 | I/O control for devices (Set for = '�r� �U')
2018-12-17T22:45:44.12962652Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:45:44.131200954Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:45:44.132785273Z 48 PC: 13c02 | Get DOS version
2018-12-17T22:45:44.135469111Z 60 PC: 13a40 | Create or truncate file
2018-12-17T22:45:44.236712842Z 65 PC: 13b89 | Delete file (Filename = '�')
2018-12-17T22:45:44.250019501Z 26 PC: 13185 | Set disk transfer address
2018-12-17T22:45:44.252715906Z 78 PC: 13191 | Find first file
2018-12-17T22:45:44.261489759Z 26 PC: 13185 | Set disk transfer address
2018-12-17T22:45:44.262682902Z 78 PC: 13191 | Find first file
2018-12-17T22:45:44.271546339Z 86 PC: 13bcd | Rename file
2018-12-17T22:45:44.286062961Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:44.287611368Z 37 PC: 132fd | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:44.289830026Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:44.291430313Z 37 PC: 132fd | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:45:44.293494041Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:44.296048924Z 37 PC: 132fd | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:45:44.298677596Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:44.300809847Z 37 PC: 132fd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:44.302411208Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:44.304362094Z 37 PC: 132fd | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:44.306050169Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:44.30835331Z 37 PC: 132fd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:44.311074676Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:44.312752985Z 37 PC: 132fd | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:45:44.314398908Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:44.317099717Z 37 PC: 132fd | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:45:44.318799481Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:44.320483635Z 37 PC: 132fd | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:45:44.323429991Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:44.324703818Z 37 PC: 132fd | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:45:44.325942493Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:44.327190037Z 37 PC: 132fd | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:45:44.328944006Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:44.330301018Z 37 PC: 132fd | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:45:44.33159458Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:44.33381435Z 37 PC: 132fd | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:45:44.335143066Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:44.336403824Z 37 PC: 132fd | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:45:44.338821409Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:44.340310402Z 37 PC: 132fd | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:45:44.34171387Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:44.346936749Z 37 PC: 132fd | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:45:44.349285726Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:44.351570462Z 37 PC: 132fd | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:45:44.354389485Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:44.357068184Z 37 PC: 132fd | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:45:44.358736256Z 53 PC: 132f4 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:44.361894099Z 37 PC: 132fd | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:45:44.364169235Z 41 PC: 132ab | Parse filename
2018-12-17T22:45:44.366236344Z 41 PC: 132b9 | Parse filename
2018-12-17T22:45:44.36819653Z 75 PC: 132c4 | Execute program
2018-12-17T22:45:44.392337939Z 80 PC: 16449 | Set current PSP
2018-12-17T22:45:44.393092777Z 48 PC: 1644e | Get DOS version
2018-12-17T22:45:44.39476022Z 99 PC: 1cc30 | Get DBCS lead byte table pointer
2018-12-17T22:45:44.398762603Z 101 PC: 164d4 | Get extended country info
2018-12-17T22:45:44.400250815Z 99 PC: 164da | Get DBCS lead byte table pointer
2018-12-17T22:45:44.401693269Z 74 PC: 1653c | Reallocate memory
2018-12-17T22:45:44.404406172Z 25 PC: 16573 | Get default drive
2018-12-17T22:45:44.406174738Z 37 PC: 16033 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:45:44.407466405Z 37 PC: 1603a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:44.412533212Z 37 PC: 16041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:44.417502579Z 74 PC: 151dc | Reallocate memory
2018-12-17T22:45:44.420242247Z 72 PC: 1521d | Allocate memory
2018-12-17T22:45:44.42302073Z 72 PC: 15255 | Allocate memory
2018-12-17T22:45:44.425277526Z 72 PC: 1525d | Allocate memory