Sample viewer

vx.netlux.org/Trojan.DOS.GDE

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:51.815195892Z 53 PC: 13412 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:51.816833979Z 53 PC: 13412 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:51.818645964Z 53 PC: 13412 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:51.821396792Z 53 PC: 13412 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:51.823037184Z 53 PC: 13412 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:51.824588909Z 53 PC: 13412 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:51.827398438Z 53 PC: 13412 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:51.829359953Z 53 PC: 13412 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:51.831315236Z 53 PC: 13412 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:51.835280356Z 53 PC: 13412 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:51.836938602Z 53 PC: 13412 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:51.838617907Z 53 PC: 13412 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:51.840247388Z 53 PC: 13412 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:51.842838737Z 53 PC: 13412 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:51.844266148Z 53 PC: 13412 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:51.846737121Z 53 PC: 13412 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:51.849359117Z 53 PC: 13412 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:51.851602662Z 53 PC: 13412 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:51.853878347Z 53 PC: 13412 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:51.856779107Z 37 PC: 13427 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:51.858389071Z 37 PC: 1342f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:51.860510587Z 37 PC: 13437 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:51.863011325Z 37 PC: 1343f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:51.865689778Z 68 PC: 137af | I/O control for devices (Set for = '')
2018-12-17T22:49:51.972433313Z 37 PC: 12e35 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:52.000470829Z 37 PC: 13526 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:52.002705407Z 37 PC: 13526 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:49:52.004457298Z 37 PC: 13526 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:49:52.006852077Z 37 PC: 13526 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:52.00852455Z 37 PC: 13526 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:52.013736552Z 37 PC: 13526 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:52.015368167Z 37 PC: 13526 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:49:52.018879053Z 37 PC: 13526 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:49:52.020404869Z 37 PC: 13526 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:49:52.022010987Z 37 PC: 13526 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:49:52.027136026Z 37 PC: 13526 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:49:52.031601245Z 37 PC: 13526 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:49:52.034255892Z 37 PC: 13526 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:49:52.037099214Z 37 PC: 13526 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:49:52.041192495Z 37 PC: 13526 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:49:52.043928886Z 37 PC: 13526 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:49:52.04697021Z 37 PC: 13526 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:49:52.049629085Z 37 PC: 13526 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:49:52.051487596Z 37 PC: 13526 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:49:52.05284691Z 76 PC: 13565 | Terminate with return code (Return code = '0')