Sample viewer

vx.netlux.org/Trojan.DOS.Thunder

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:23.493997712Z 48 PC: 12a54 | Get DOS version
2018-12-17T22:51:23.495402951Z 74 PC: 12ab2 | Reallocate memory
2018-12-17T22:51:23.519099948Z 48 PC: 12b22 | Get DOS version
2018-12-17T22:51:23.520676269Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:23.522194261Z 37 PC: 12b3c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:23.524949116Z 68 PC: 12bc0 | I/O control for devices (Set for = '����3ҋڋȋ����3� �y����ڋȋ� �y���ك�')
2018-12-17T22:51:23.527550383Z 68 PC: 12bc0 | I/O control for devices (Set for = '�')
2018-12-17T22:51:23.53014671Z 68 PC: 12bc0 | I/O control for devices (Set for = 'F9��')
2018-12-17T22:51:23.533740321Z 68 PC: 12bc0 | I/O control for devices (Set for = ' �t �^����')
2018-12-17T22:51:23.538254822Z 68 PC: 12bc0 | I/O control for devices (Set for = ' �t �^����')
2018-12-17T22:51:23.54207029Z 48 PC: 15bbc | Get DOS version
2018-12-17T22:51:23.54486493Z 37 PC: 15bec | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:23.548515858Z 72 PC: 275d5 | Allocate memory
2018-12-17T22:51:23.551990215Z 72 PC: 275e6 | Allocate memory
2018-12-17T22:51:23.556623388Z 53 PC: 3410d | Get interrupt vector (Interrupt = '103' AKA 'Set handle count')
2018-12-17T22:51:23.569924977Z 37 PC: 18374 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:23.593636992Z 61 PC: 15d28 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:23.603605849Z 66 PC: 15dca | Move file pointer
2018-12-17T22:51:23.605553959Z 63 PC: 15d74 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T22:51:23.618455225Z 66 PC: 15dca | Move file pointer
2018-12-17T22:51:23.620543257Z 63 PC: 15d74 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T22:51:23.642255075Z 66 PC: 15dca | Move file pointer
2018-12-17T22:51:23.644938275Z 63 PC: 15d74 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T22:51:23.663458046Z 66 PC: 15dca | Move file pointer
2018-12-17T22:51:23.665726177Z 63 PC: 15d74 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T22:51:23.713350975Z 66 PC: 15dca | Move file pointer
2018-12-17T22:51:23.71549864Z 63 PC: 15d74 | Read file or device (Read 1024 bytes on handle 5)
2018-12-17T22:51:23.733359732Z 66 PC: 15dca | Move file pointer
2018-12-17T22:51:23.735108157Z 63 PC: 15d74 | Read file or device (Read 1024 bytes on handle 5)