Sample viewer

vx.netlux.org/Trojan.DOS.Neutron

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:43.876138624Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.878323988Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:43.879807954Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:43.881251448Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:43.883015652Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:43.884452425Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:43.886621217Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:43.888225293Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:43.890428985Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:43.891732997Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:43.89321371Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:43.902479487Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:43.904018494Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:43.905545017Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:43.909779039Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:43.911112644Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:43.912533338Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:43.914475883Z 53 PC: 12fa6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:43.916124406Z 37 PC: 12fbb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.917818279Z 37 PC: 12fc3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:43.919678822Z 37 PC: 12fcb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:43.921000439Z 37 PC: 12fd3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:43.922725955Z 68 PC: 132c2 | I/O control for devices (Set for = '')
2018-12-17T22:52:43.925182047Z 48 PC: 13647 | Get DOS version
2018-12-17T22:52:43.928871372Z 61 PC: 1345c | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:52:43.936747053Z 87 PC: 12e10 | Get or set file date and time
2018-12-17T22:52:43.939401527Z 42 PC: 12d97 | Get date 0x12d97: xor ah, ah
0x12d99: les di, ptr [bp + 6]
0x12d9c: stosw word ptr es:[di], ax
0x12d9d: mov al, dl
0x12d9f: les di, ptr [bp + 0xa]
0x12da2: stosw word ptr es:[di], ax
0x12da3: mov al, dh
0x12da5: les di, ptr [bp + 0xe]
0x12da8: stosw word ptr es:[di], ax
0x12da9: xchg ax, cx
0x12daa: les di, ptr [bp + 0x12]
0x12dad: stosw word ptr es:[di], ax
0x12dae: pop bp
0x12daf: retf 0x10
0x12db2: push bp
0x12db3: mov bp, sp
0x12db5: mov cx, word ptr [bp + 0xa]
0x12db8: mov dh, byte ptr [bp + 8]
0x12dbb: mov dl, byte ptr [bp + 6]
0x12dbe: mov ah, 0x2b
2018-12-17T22:52:43.941967485Z 44 PC: 12dcd | Get time 0x12dcd: xor ah, ah
0x12dcf: mov al, dl
0x12dd1: les di, ptr [bp + 6]
0x12dd4: stosw word ptr es:[di], ax
0x12dd5: mov al, dh
0x12dd7: les di, ptr [bp + 0xa]
0x12dda: stosw word ptr es:[di], ax
0x12ddb: mov al, cl
0x12ddd: les di, ptr [bp + 0xe]
0x12de0: stosw word ptr es:[di], ax
0x12de1: mov al, ch
0x12de3: les di, ptr [bp + 0x12]
0x12de6: stosw word ptr es:[di], ax
0x12de7: pop bp
0x12de8: retf 0x10
0x12deb: push bp
0x12dec: mov bp, sp
0x12dee: mov ch, byte ptr [bp + 0xc]
0x12df1: mov cl, byte ptr [bp + 0xa]
0x12df4: mov dh, byte ptr [bp + 8]
2018-12-17T22:52:43.944611376Z 53 PC: 12ece | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:52:43.947360729Z 37 PC: 12eea | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:52:43.948624224Z 48 PC: 13647 | Get DOS version
2018-12-17T22:52:43.950180585Z 37 PC: 12eea | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:52:43.95351531Z 64 PC: 133c5 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:52:43.955535723Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.956966207Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:52:43.959166321Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:52:43.960526132Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:43.961866514Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:43.964187558Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:52:43.965922398Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:52:43.967030346Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:52:43.968366932Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:52:43.970290593Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:52:43.971400777Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:52:43.972719578Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:52:43.974737182Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:52:43.976132017Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:52:43.977630496Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:52:43.979470156Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:52:43.980605431Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:52:43.981974439Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:52:43.983931453Z 76 PC: 130f4 | Terminate with return code (Return code = '0')