Sample viewer

vx.netlux.org/Trojan.DOS.Nodos

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:15:26.671319131Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:15:26.674873966Z 41 PC: 94fae | Parse filename
2018-12-17T23:15:26.677467239Z 41 PC: 9502f | Parse filename
2018-12-17T23:15:26.678700315Z 41 PC: 9504c | Parse filename
2018-12-17T23:15:26.679997804Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T23:15:26.681313775Z 71 PC: 986f3 | Get current directory
2018-12-17T23:15:26.6837967Z 78 PC: 986fe | Find first file
2018-12-17T23:15:26.689323908Z 71 PC: 986f3 | Get current directory
2018-12-17T23:15:26.691060896Z 78 PC: 986fe | Find first file
2018-12-17T23:15:26.696882422Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T23:15:26.699469375Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:15:26.700482304Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:15:26.701261409Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:26.701923871Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.703123519Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.704042456Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.704875057Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.706108545Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.707059716Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.707939045Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.70926402Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.710191122Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.711025079Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.712193578Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.713221656Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.714125603Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.71514459Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.716296426Z 62 PC: 122ab | Close file
2018-12-17T23:15:26.717382909Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T23:15:26.718168025Z 56 PC: 94df9 | Get or set country info
2018-12-17T23:15:26.719448769Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:15:26.721917655Z 25 PC: 94e62 | Get default drive
2018-12-17T23:15:26.722865708Z 71 PC: 970dd | Get current directory
2018-12-17T23:15:26.725505512Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:15:26.72740605Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T23:15:26.729034012Z 93 PC: 94f20 | File sharing functions
2018-12-17T23:15:26.730451957Z 93 PC: 94f27 | File sharing functions
2018-12-17T23:15:26.73155561Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T23:15:41.718268923Z 0 PC: 0 | Program terminate
2018-12-17T23:15:43.073140539Z 0 PC: 0 | Program terminate
2018-12-17T23:15:43.175899062Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:15:43.182053995Z 41 PC: 94fae | Parse filename
2018-12-17T23:15:43.183696663Z 41 PC: 9502f | Parse filename
2018-12-17T23:15:43.185039232Z 41 PC: 9504c | Parse filename
2018-12-17T23:15:43.188936902Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T23:15:43.190470262Z 71 PC: 986f3 | Get current directory
2018-12-17T23:15:43.200444931Z 78 PC: 986fe | Find first file
2018-12-17T23:15:43.21043266Z 71 PC: 9856c | Get current directory
2018-12-17T23:15:43.213371483Z 73 PC: 97c09 | Release memory
2018-12-17T23:15:43.215783393Z 75 PC: 11821 | Execute program
2018-12-17T23:15:43.230535838Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T23:15:43.236852832Z 76 PC: 12a4b | Terminate with return code (Return code = '36')