Sample viewer

vx.netlux.org/Trojan.DOS.Elephant2

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:31.126883294Z 53 PC: 13386 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:31.129065673Z 53 PC: 13386 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:31.131796813Z 53 PC: 13386 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:31.135489921Z 53 PC: 13386 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:31.137149468Z 53 PC: 13386 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:31.139568572Z 53 PC: 13386 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:31.141225024Z 53 PC: 13386 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:31.142940055Z 53 PC: 13386 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:31.15199281Z 53 PC: 13386 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:31.153705958Z 53 PC: 13386 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:31.155361378Z 53 PC: 13386 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:31.15839188Z 53 PC: 13386 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:31.160246724Z 53 PC: 13386 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:31.162069368Z 53 PC: 13386 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:31.165210228Z 53 PC: 13386 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:31.166810244Z 53 PC: 13386 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:31.168887105Z 53 PC: 13386 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:31.170623867Z 53 PC: 13386 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:31.172900834Z 37 PC: 1339b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:31.174766148Z 37 PC: 133a3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:31.176124349Z 37 PC: 133ab | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:31.177880698Z 37 PC: 133b3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:31.179485072Z 68 PC: 136a2 | I/O control for devices (Set for = '')
2018-12-17T22:53:31.206050654Z 37 PC: 12c27 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:31.209580916Z 53 PC: 13226 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:31.211373322Z 37 PC: 13242 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:53:31.212908726Z 53 PC: 13258 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:31.215445241Z 37 PC: 13261 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:31.216872973Z 53 PC: 13258 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:31.218500771Z 37 PC: 13261 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:31.220382846Z 53 PC: 13258 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:31.22167342Z 37 PC: 13261 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:31.222790919Z 53 PC: 13258 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:31.224323638Z 37 PC: 13261 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:31.226237423Z 53 PC: 13258 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:31.227337389Z 37 PC: 13261 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:31.228573912Z 53 PC: 13258 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:31.23029262Z 37 PC: 13261 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:31.231812596Z 53 PC: 13258 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:31.233086709Z 37 PC: 13261 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:31.234959707Z 53 PC: 13258 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:31.236386047Z 37 PC: 13261 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:31.237643919Z 53 PC: 13258 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:31.239469028Z 37 PC: 13261 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:31.24076376Z 53 PC: 13258 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:31.242575653Z 37 PC: 13261 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:31.244450996Z 53 PC: 13258 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:31.245631083Z 37 PC: 13261 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:31.246797173Z 53 PC: 13258 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:31.248890736Z 37 PC: 13261 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:31.250671331Z 53 PC: 13258 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:31.251831289Z 37 PC: 13261 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:31.255378372Z 53 PC: 13258 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:31.256725984Z 37 PC: 13261 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:31.2580174Z 53 PC: 13258 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:31.261891777Z 37 PC: 13261 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:31.263648627Z 53 PC: 13258 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:31.265067232Z 37 PC: 13261 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:31.266803794Z 53 PC: 13258 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:31.269721055Z 37 PC: 13261 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:31.271417852Z 53 PC: 13258 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:31.273090914Z 37 PC: 13261 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:31.275561856Z 41 PC: 132fa | Parse filename
2018-12-17T22:53:31.277525545Z 41 PC: 13308 | Parse filename
2018-12-17T22:53:31.27942922Z 75 PC: 13313 | Execute program
2018-12-17T22:53:31.287431983Z 53 PC: 13258 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:31.288891795Z 37 PC: 13261 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:31.290212476Z 53 PC: 13258 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:31.292802551Z 37 PC: 13261 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:31.294460756Z 53 PC: 13258 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:31.295987854Z 37 PC: 13261 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:31.298214868Z 53 PC: 13258 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:31.299964444Z 37 PC: 13261 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:31.301478729Z 53 PC: 13258 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:31.304087659Z 37 PC: 13261 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:31.305619777Z 53 PC: 13258 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:31.311946812Z 37 PC: 13261 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:31.313612391Z 53 PC: 13258 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:31.316193058Z 37 PC: 13261 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:31.31778044Z 53 PC: 13258 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:31.319376378Z 37 PC: 13261 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:31.327148968Z 53 PC: 13258 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:31.334373609Z 37 PC: 13261 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:31.335662891Z 53 PC: 13258 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:31.337810526Z 37 PC: 13261 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:31.339282591Z 53 PC: 13258 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:31.341402973Z 37 PC: 13261 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:31.343946742Z 53 PC: 13258 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:31.345346972Z 37 PC: 13261 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:31.346621787Z 53 PC: 13258 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:31.348615101Z 37 PC: 13261 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:31.351184307Z 53 PC: 13258 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:31.352796035Z 37 PC: 13261 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:31.354434152Z 53 PC: 13258 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:31.356090373Z 37 PC: 13261 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:31.357844287Z 53 PC: 13258 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:31.359519224Z 37 PC: 13261 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:31.361825005Z 53 PC: 13258 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:31.36306819Z 37 PC: 13261 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:31.365098484Z 53 PC: 13258 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:31.367230128Z 37 PC: 13261 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:31.371107111Z 49 PC: 13295 | Terminate and stay resident (Return code = '0' | Memory size = '402')