Sample viewer

vx.netlux.org/Virus.DOS.HLLC.Rider.4000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:17.3773253Z 53 PC: 13316 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:17.381569793Z 53 PC: 13316 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:17.383430263Z 53 PC: 13316 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:17.384605155Z 53 PC: 13316 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:17.397557387Z 53 PC: 13316 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:17.398844288Z 53 PC: 13316 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:17.400268921Z 53 PC: 13316 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:17.402538962Z 53 PC: 13316 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:17.404059178Z 53 PC: 13316 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:17.405562157Z 53 PC: 13316 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:17.408097922Z 53 PC: 13316 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:17.409590677Z 53 PC: 13316 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:17.41100707Z 53 PC: 13316 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:17.413081959Z 53 PC: 13316 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:17.414445804Z 53 PC: 13316 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:17.415925447Z 53 PC: 13316 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:17.41810675Z 53 PC: 13316 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:17.420469109Z 53 PC: 13316 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:17.422371306Z 37 PC: 1332b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:17.423776101Z 37 PC: 13333 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:17.433911677Z 37 PC: 1333b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:17.435762435Z 37 PC: 13343 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:17.437957083Z 68 PC: 1388f | I/O control for devices (Set for = '')
2018-12-17T21:58:17.441000616Z 48 PC: 13d65 | Get DOS version
2018-12-17T21:58:17.442730311Z 48 PC: 13d65 | Get DOS version
2018-12-17T21:58:17.44434864Z 48 PC: 13d65 | Get DOS version
2018-12-17T21:58:17.447488103Z 60 PC: 13bb1 | Create or truncate file
2018-12-17T21:58:17.464525893Z 65 PC: 13cfa | Delete file (Filename = '')
2018-12-17T21:58:17.482848753Z 26 PC: 13135 | Set disk transfer address
2018-12-17T21:58:17.485998382Z 78 PC: 13141 | Find first file
2018-12-17T21:58:17.492523634Z 26 PC: 13135 | Set disk transfer address
2018-12-17T21:58:17.494250935Z 78 PC: 13141 | Find first file
2018-12-17T21:58:17.499533059Z 86 PC: 13d30 | Rename file
2018-12-17T21:58:17.509499218Z 53 PC: 1319c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:17.527174736Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:17.529409523Z 53 PC: 1319c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:17.531141339Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:17.53247938Z 53 PC: 1319c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:17.5347188Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:58:17.536116886Z 53 PC: 1319c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:17.53744062Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:17.5392759Z 53 PC: 1319c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:17.540493645Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:17.541663006Z 53 PC: 1319c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:17.543456687Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:17.545302791Z 53 PC: 1319c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:17.54658685Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:17.548769455Z 53 PC: 1319c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:17.550684995Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:17.55160812Z 53 PC: 1319c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:17.552757819Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:17.554147828Z 53 PC: 1319c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:17.555549658Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:17.557173762Z 53 PC: 1319c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:17.569849632Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:17.571373488Z 53 PC: 1319c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:17.573297202Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:17.575077323Z 53 PC: 1319c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:17.576177274Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:17.577634294Z 53 PC: 1319c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:17.579182414Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:17.580515393Z 53 PC: 1319c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:17.581987418Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:17.583576851Z 53 PC: 1319c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:17.584568527Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:17.585699683Z 53 PC: 1319c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:17.587239038Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:58:17.588441221Z 53 PC: 1319c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:17.589465844Z 37 PC: 131a5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:58:17.592555393Z 41 PC: 13224 | Parse filename
2018-12-17T21:58:17.594368476Z 41 PC: 13232 | Parse filename
2018-12-17T21:58:17.596264626Z 75 PC: 1323d | Execute program
2018-12-17T21:58:17.618873206Z 80 PC: 15ea9 | Set current PSP
2018-12-17T21:58:17.619715059Z 48 PC: 15eae | Get DOS version
2018-12-17T21:58:17.621494844Z 99 PC: 1c690 | Get DBCS lead byte table pointer
2018-12-17T21:58:17.625098403Z 101 PC: 15f34 | Get extended country info
2018-12-17T21:58:17.627143141Z 99 PC: 15f3a | Get DBCS lead byte table pointer
2018-12-17T21:58:17.628421407Z 74 PC: 15f9c | Reallocate memory
2018-12-17T21:58:17.63095973Z 25 PC: 15fd3 | Get default drive
2018-12-17T21:58:17.6323752Z 37 PC: 15a93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:58:17.633568864Z 37 PC: 15a9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:17.636209389Z 37 PC: 15aa1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:17.640492504Z 74 PC: 14c3c | Reallocate memory
2018-12-17T21:58:17.642180206Z 72 PC: 14c7d | Allocate memory
2018-12-17T21:58:17.644988661Z 72 PC: 14cb5 | Allocate memory
2018-12-17T21:58:17.646831504Z 72 PC: 14cbd | Allocate memory