Sample viewer

vx.netlux.org/Trojan.DOS.Synfo

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:32.786910833Z 48 PC: 173ec | Get DOS version
2018-12-17T22:51:32.789297626Z 74 PC: 1743c | Reallocate memory
2018-12-17T22:51:32.792609848Z 48 PC: 174a0 | Get DOS version
2018-12-17T22:51:32.794106891Z 53 PC: 174a8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:32.7965182Z 37 PC: 174ba | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:32.802188293Z 53 PC: 19b42 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:32.803269975Z 37 PC: 19b52 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:32.805037054Z 53 PC: 19b57 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:32.806261384Z 37 PC: 19b67 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:32.807755441Z 53 PC: 17896 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:32.809102642Z 53 PC: 17896 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:32.810504415Z 53 PC: 17896 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:32.81160343Z 53 PC: 17896 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:32.812832168Z 53 PC: 17896 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:32.82206944Z 53 PC: 17896 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:32.823371025Z 53 PC: 17896 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:32.824626554Z 53 PC: 17896 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:32.826624898Z 53 PC: 17896 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:32.82804726Z 53 PC: 17896 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:32.829251182Z 53 PC: 17896 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:32.831091369Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:32.832262649Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:32.833566128Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:32.841755232Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:32.843175159Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:32.844376817Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:32.846534961Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:32.848182275Z 37 PC: 178c5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:32.849870517Z 37 PC: 178cc | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:32.853275553Z 37 PC: 178d1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:32.855433046Z 68 PC: 1754b | I/O control for devices (Set for = '����')
2018-12-17T22:51:32.857414038Z 68 PC: 1754b | I/O control for devices
2018-12-17T22:51:32.860622966Z 68 PC: 1754b | I/O control for devices (Set for = '')
2018-12-17T22:51:32.864824539Z 68 PC: 1754b | I/O control for devices (Set for = '')
2018-12-17T22:51:32.866841669Z 68 PC: 1754b | I/O control for devices (Set for = '')
2018-12-17T22:51:32.869425753Z 53 PC: 1538e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:32.872015478Z 53 PC: 1539b | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:51:32.873980139Z 53 PC: 153a8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:32.875914152Z 37 PC: 153bd | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:32.880739496Z 37 PC: 153c5 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:51:32.881987411Z 37 PC: 153cd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:32.883588849Z 53 PC: 15e4c | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:51:32.8853672Z 53 PC: 15e59 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:51:32.886912513Z 53 PC: 15e68 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:51:32.889954116Z 37 PC: 15e75 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:51:32.891435489Z 53 PC: 15e7c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:32.893652233Z 37 PC: 15e89 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:51:32.895322852Z 53 PC: 15e95 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:32.900261961Z 48 PC: 15f57 | Get DOS version
2018-12-17T22:51:32.903146329Z 74 PC: 13ab1 | Reallocate memory
2018-12-17T22:51:32.905847273Z 74 PC: 13ab1 | Reallocate memory
2018-12-17T22:51:32.907720212Z 68 PC: 15304 | I/O control for devices (Set for = 'nul)')
2018-12-17T22:51:32.910280321Z 68 PC: 15304 | I/O control for devices (Set for = '')
2018-12-17T22:51:32.911775079Z 51 PC: 15322 | Get or set Ctrl-Break
2018-12-17T22:51:32.912714574Z 51 PC: 1532e | Get or set Ctrl-Break
2018-12-17T22:51:32.917087008Z 72 PC: 12c86 | Allocate memory
2018-12-17T22:51:32.919478069Z 74 PC: 13ab1 | Reallocate memory
2018-12-17T22:51:32.921844284Z 72 PC: 12c86 | Allocate memory
2018-12-17T22:51:32.925625628Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:51:32.93685838Z 37 PC: 14050 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:35.712893729Z 73 PC: 12c86 | Release memory
2018-12-17T22:51:35.716736779Z 74 PC: 13ab1 | Reallocate memory
2018-12-17T22:51:35.719097674Z 51 PC: 15339 | Get or set Ctrl-Break
2018-12-17T22:51:35.720393328Z 53 PC: 134de | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:35.722851886Z 53 PC: 134eb | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:35.724734623Z 53 PC: 134f8 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:51:35.726449625Z 37 PC: 13513 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:35.729395179Z 53 PC: 1351b | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:51:35.731288405Z 37 PC: 13528 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:51:35.743785892Z 53 PC: 1352f | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:51:35.745898331Z 37 PC: 1353c | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:35.748137587Z 37 PC: 13546 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:51:35.76302295Z 37 PC: 13551 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:51:35.76468394Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:35.767306898Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:35.768853093Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:35.770472525Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:35.772586947Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:35.774094299Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:35.775614675Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:35.777888106Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:35.779313473Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:35.780819352Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:35.78309104Z 37 PC: 178e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:35.784963988Z 37 PC: 19b76 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:35.786561569Z 37 PC: 175fc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:35.789309301Z 41 PC: 172e5 | Parse filename
2018-12-17T22:51:35.791631143Z 41 PC: 172e7 | Parse filename
2018-12-17T22:51:35.793372243Z 41 PC: 172ec | Parse filename
2018-12-17T22:51:35.795143892Z 75 PC: 17302 | Execute program
2018-12-17T22:51:35.812859302Z 80 PC: 1cc49 | Set current PSP
2018-12-17T22:51:35.813828412Z 48 PC: 1cc4e | Get DOS version
2018-12-17T22:51:35.815379416Z 99 PC: 23430 | Get DBCS lead byte table pointer
2018-12-17T22:51:35.818554841Z 101 PC: 1ccd4 | Get extended country info
2018-12-17T22:51:35.819926458Z 99 PC: 1ccda | Get DBCS lead byte table pointer
2018-12-17T22:51:35.821605512Z 74 PC: 1cd3c | Reallocate memory
2018-12-17T22:51:35.82351546Z 25 PC: 1cd73 | Get default drive
2018-12-17T22:51:35.824639922Z 37 PC: 1c833 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:51:35.826051544Z 37 PC: 1c83a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:35.831654569Z 37 PC: 1c841 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:35.836819542Z 74 PC: 1b9dc | Reallocate memory
2018-12-17T22:51:35.839009867Z 72 PC: 1ba1d | Allocate memory
2018-12-17T22:51:35.842120179Z 72 PC: 1ba55 | Allocate memory
2018-12-17T22:51:35.844742797Z 72 PC: 1ba5d | Allocate memory