Sample viewer

vx.netlux.org/Virus.DOS.EasyRider.2108

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:21.73346656Z 51 PC: 12a60 | Get or set Ctrl-Break
2018-12-17T22:47:21.735354648Z 82 PC: 9f41c | Get DOS internal pointers (SYSVARS)
2018-12-17T22:47:21.739091418Z 48 PC: 9fa53 | Get DOS version
2018-12-17T22:47:21.740532065Z 98 PC: 9fa53 | Get current PSP
2018-12-17T22:47:21.741581025Z 61 PC: 9fa53 | Open file (Filename = 't)[KS3���')
2018-12-17T22:47:21.763914374Z 63 PC: 9fa53 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:47:21.767268796Z 64 PC: 9fa53 | Write file or device (Write 2108 bytes on handle 5)
2018-12-17T22:47:22.108664652Z 64 PC: 9fa53 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:47:22.112560851Z 62 PC: 9fa53 | Close file
2018-12-17T22:47:22.122950491Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:47:22.126529886Z 72 PC: 12174 | Allocate memory
2018-12-17T22:47:22.130290792Z 72 PC: 1218d | Allocate memory
2018-12-17T22:47:22.134643399Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:47:22.137160087Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:22.1402439Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:22.142344196Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.145588111Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.148863104Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.151313498Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.153320869Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.155842286Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.158679006Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.161172821Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.163500243Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.166992544Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.169958757Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.172530278Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.175703961Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.178519401Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.181114115Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.184830618Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.187341435Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.19061272Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.193937417Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.196865207Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.199224811Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.202663271Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.205158809Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.207452448Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.209803025Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.21286098Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.215175568Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.217488443Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.220069362Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:22.22242604Z 62 PC: 122ab | Close file
2018-12-17T22:47:22.226457524Z 99 PC: 99d67 | Get DBCS lead byte table pointer
2018-12-17T22:47:22.230320431Z 56 PC: 94589 | Get or set country info
2018-12-17T22:47:22.233331188Z 64 PC: 99fd8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:47:22.239706986Z 25 PC: 945f2 | Get default drive
2018-12-17T22:47:22.243410253Z 71 PC: 9686d | Get current directory
2018-12-17T22:47:22.248579385Z 64 PC: 99fd8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:47:22.253598645Z 2 PC: 96842 | Character output (Char = '3e')
2018-12-17T22:47:22.257966211Z 93 PC: 946b0 | File sharing functions
2018-12-17T22:47:22.261219282Z 93 PC: 946b7 | File sharing functions
2018-12-17T22:47:22.264275344Z 10 PC: 946c9 | Buffered keyboard input
2018-12-17T22:47:36.714434221Z 0 PC: 0 | Program terminate
2018-12-17T22:47:38.069572422Z 0 PC: 0 | Program terminate
2018-12-17T22:47:38.173944938Z 64 PC: 99fd8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:47:38.181838688Z 41 PC: 9473e | Parse filename
2018-12-17T22:47:38.188638723Z 41 PC: 947bf | Parse filename
2018-12-17T22:47:38.200961764Z 41 PC: 947dc | Parse filename
2018-12-17T22:47:38.205055075Z 26 PC: 97c87 | Set disk transfer address
2018-12-17T22:47:38.20837898Z 71 PC: 97e83 | Get current directory
2018-12-17T22:47:38.217754082Z 78 PC: 9fa53 | Find first file
2018-12-17T22:47:38.229510669Z 71 PC: 97cfc | Get current directory
2018-12-17T22:47:38.233974095Z 73 PC: 97399 | Release memory
2018-12-17T22:47:38.236259028Z 44 PC: 9fa53 | Get time 0x9fa53: ret
0x9fa54: cli
0x9fa55: pushf
0x9fa56: lcall ptr cs:[0x858]
0x9fa5b: ret
0x9fa5c: mov al, 3
0x9fa5e: iret
0x9fa5f: in ax, 0x40
0x9fa61: and ax, 0x7f
0x9fa64: inc ax
0x9fa65: mov word ptr cs:[0x866], ax
0x9fa69: in ax, 0x40
0x9fa6b: and ax, 0xf000
0x9fa6e: mov word ptr cs:[0x868], ax
0x9fa72: ret
0x9fa73: add byte ptr [bx + di], al
0x9fa75: pushaw
0x9fa76: dec word ptr cs:[0x866]
0x9fa7b: jne 0x9fa93
0x9fa7d: push ds
2018-12-17T22:47:38.239864582Z 61 PC: 9fa53 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:47:38.248280874Z 63 PC: 9fa53 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:47:38.255276927Z 64 PC: 9fa53 | Write file or device (Write 2108 bytes on handle 5)
2018-12-17T22:47:38.271283508Z 64 PC: 9fa53 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:47:38.279442417Z 62 PC: 9fa53 | Close file
2018-12-17T22:47:38.288780891Z 75 PC: 11821 | Execute program
2018-12-17T22:47:38.306127089Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:47:38.311830154Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:47:38.317091459Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:47:38.319880428Z 72 PC: 12174 | Allocate memory
2018-12-17T22:47:38.326602367Z 72 PC: 1218d | Allocate memory
2018-12-17T22:47:38.328839399Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:47:38.330769806Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:38.344895464Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:38.347173033Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.350244002Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.35321824Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.356681887Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.35975996Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.363183612Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.365664503Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.368520459Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.371754564Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.374458594Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.376905481Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.38007721Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.38226451Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.384532982Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.387703678Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.390447172Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.39304344Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.397235185Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.400393368Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.402934502Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.407820251Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.411543035Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.414222649Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.41710794Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.419277316Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.421189258Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.422907145Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.425266528Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.427296592Z 69 PC: 9fa53 | Duplicate handle
2018-12-17T22:47:38.429129585Z 62 PC: 122ab | Close file
2018-12-17T22:47:38.432734648Z 99 PC: 99d67 | Get DBCS lead byte table pointer
2018-12-17T22:47:38.434706202Z 56 PC: 94589 | Get or set country info
2018-12-17T22:47:38.436849729Z 64 PC: 99fd8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:47:38.441645468Z 25 PC: 945f2 | Get default drive
2018-12-17T22:47:38.444630577Z 71 PC: 9686d | Get current directory
2018-12-17T22:47:38.450201333Z 64 PC: 99fd8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:47:38.455788219Z 2 PC: 96842 | Character output (Char = '3e')
2018-12-17T22:47:38.459980645Z 93 PC: 946b0 | File sharing functions
2018-12-17T22:47:38.463683532Z 93 PC: 946b7 | File sharing functions
2018-12-17T22:47:38.469353544Z 10 PC: 946c9 | Buffered keyboard input