Sample viewer

vx.netlux.org/Trojan.DOS.Membrain

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:01.51477983Z 48 PC: 1bf9c | Get DOS version
2018-12-17T22:53:01.517111022Z 74 PC: 1bfec | Reallocate memory
2018-12-17T22:53:01.519928052Z 48 PC: 1bbee | Get DOS version
2018-12-17T22:53:01.521486149Z 53 PC: 1bbf6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:01.523408375Z 37 PC: 1bc08 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:01.547811547Z 53 PC: 1ea22 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:01.54923403Z 37 PC: 1ea32 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:01.550568386Z 53 PC: 1ea37 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:01.552751567Z 37 PC: 1ea47 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:01.554491909Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:01.556265945Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:01.56242348Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:01.566405638Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:01.574408123Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:01.578717583Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:01.584301099Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:01.586150702Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:01.588668061Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:01.591238396Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:01.593603216Z 53 PC: 1c776 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:01.59865826Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:01.600562463Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:01.602520949Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:01.604442426Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:01.608403973Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:01.610580624Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:01.614690113Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:01.619699023Z 37 PC: 1c7a5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:01.621416147Z 37 PC: 1c7ac | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:01.622941378Z 37 PC: 1c7b1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:01.626826946Z 68 PC: 1bc99 | I/O control for devices (Set for = '����t@�D�!���]�')
2018-12-17T22:53:01.629011234Z 68 PC: 1bc99 | I/O control for devices (Set for = '���������tR�V������u �� u@��u��u�4���t��t �'���u ��?�6')
2018-12-17T22:53:01.631211144Z 68 PC: 1bc99 | I/O control for devices (Set for = ']�.��t,:�tCCC��.����s#����QS�v')
2018-12-17T22:53:01.634165469Z 68 PC: 1bc99 | I/O control for devices (Set for = '.����s#����QS�v')
2018-12-17T22:53:01.636292118Z 68 PC: 1bc99 | I/O control for devices (Set for = '.����s#����QS�v')
2018-12-17T22:53:01.638547695Z 53 PC: 18e84 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:01.644481778Z 53 PC: 18e91 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:53:01.64616832Z 53 PC: 18e9e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:01.647766576Z 37 PC: 18eb3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:01.650682502Z 37 PC: 18ebb | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:53:01.652177918Z 37 PC: 18ec3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:01.653959624Z 53 PC: 193fc | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:53:01.656823055Z 53 PC: 19409 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:53:01.65878471Z 53 PC: 19418 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:01.660647385Z 37 PC: 19425 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:53:01.663399885Z 53 PC: 1942c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:53:01.665145861Z 37 PC: 19439 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:53:01.666972608Z 53 PC: 19445 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:01.67322721Z 48 PC: 19507 | Get DOS version
2018-12-17T22:53:01.675074239Z 74 PC: 17a6d | Reallocate memory
2018-12-17T22:53:01.677052919Z 74 PC: 17a6d | Reallocate memory
2018-12-17T22:53:01.679755698Z 68 PC: 18dfa | I/O control for devices (Set for = '')
2018-12-17T22:53:01.681879999Z 68 PC: 18dfa | I/O control for devices (Set for = '')
2018-12-17T22:53:01.684085059Z 51 PC: 18e18 | Get or set Ctrl-Break
2018-12-17T22:53:01.685606422Z 51 PC: 18e24 | Get or set Ctrl-Break
2018-12-17T22:53:01.690465041Z 72 PC: 1b2ec | Allocate memory
2018-12-17T22:53:01.692746335Z 74 PC: 17a6d | Reallocate memory
2018-12-17T22:53:01.694447307Z 72 PC: 1b2ec | Allocate memory
2018-12-17T22:53:01.698688345Z 37 PC: 17129 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:01.706322266Z 73 PC: 1b2ec | Release memory
2018-12-17T22:53:01.70917486Z 74 PC: 17a6d | Reallocate memory
2018-12-17T22:53:01.712073647Z 51 PC: 18e2f | Get or set Ctrl-Break
2018-12-17T22:53:01.713376179Z 37 PC: 190b1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:01.714906685Z 37 PC: 190bb | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:53:01.717156984Z 37 PC: 190c5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:01.718831869Z 53 PC: 1749a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:53:01.727940764Z 53 PC: 174a7 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:01.73028815Z 53 PC: 174b4 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:01.731739304Z 37 PC: 174cf | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:01.733117207Z 53 PC: 174d7 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:53:01.735222075Z 37 PC: 174e4 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:01.736550054Z 53 PC: 174eb | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:53:01.737870523Z 37 PC: 174f8 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:53:01.740115053Z 37 PC: 17502 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:53:01.741436929Z 37 PC: 1750d | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:53:01.742890242Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:01.744379076Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:01.746428322Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:01.747715315Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:01.748980398Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:01.751296408Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:01.752572446Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:01.753911552Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:01.756276964Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:01.757592727Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:01.758995642Z 37 PC: 1c7c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:01.761765969Z 37 PC: 1ea56 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:01.763095483Z 37 PC: 1bd4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:01.765362765Z 41 PC: 1ba71 | Parse filename
2018-12-17T22:53:01.767853603Z 41 PC: 1ba73 | Parse filename
2018-12-17T22:53:01.769913782Z 41 PC: 1ba78 | Parse filename
2018-12-17T22:53:01.771980876Z 75 PC: 1ba8e | Execute program
2018-12-17T22:53:01.797569363Z 80 PC: 2e289 | Set current PSP
2018-12-17T22:53:01.798872432Z 48 PC: 2e28e | Get DOS version
2018-12-17T22:53:01.801052823Z 99 PC: 34a70 | Get DBCS lead byte table pointer
2018-12-17T22:53:01.804616376Z 101 PC: 2e314 | Get extended country info
2018-12-17T22:53:01.806386493Z 99 PC: 2e31a | Get DBCS lead byte table pointer
2018-12-17T22:53:01.808158068Z 74 PC: 2e37c | Reallocate memory
2018-12-17T22:53:01.810600073Z 25 PC: 2e3b3 | Get default drive
2018-12-17T22:53:01.812154317Z 37 PC: 2de73 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:53:01.813712039Z 37 PC: 2de7a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:01.816242458Z 37 PC: 2de81 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:01.821443939Z 74 PC: 2d01c | Reallocate memory
2018-12-17T22:53:01.823001139Z 72 PC: 2d05d | Allocate memory
2018-12-17T22:53:01.825607699Z 72 PC: 2d095 | Allocate memory
2018-12-17T22:53:01.827750617Z 72 PC: 2d09d | Allocate memory