Sample viewer

vx.netlux.org/Trojan.DOS.Minimat

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:58.117766745Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:53:58.137302952Z 41 PC: 94fae | Parse filename
2018-12-17T22:53:58.14570061Z 41 PC: 9502f | Parse filename
2018-12-17T22:53:58.147943248Z 41 PC: 9504c | Parse filename
2018-12-17T22:53:58.150571569Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:53:58.153452837Z 71 PC: 986f3 | Get current directory
2018-12-17T22:53:58.158190518Z 78 PC: 986fe | Find first file
2018-12-17T22:53:58.167246527Z 71 PC: 986f3 | Get current directory
2018-12-17T22:53:58.170735376Z 78 PC: 986fe | Find first file
2018-12-17T22:53:58.181235345Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T22:53:58.184341303Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:53:58.185944969Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:58.188520255Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:58.189490027Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.191056553Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.19230645Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.193528363Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.195208962Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.196479329Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.197462953Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.198951076Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.200019065Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.201203723Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.209363051Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.210357071Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.211516163Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.212907315Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.214115803Z 62 PC: 122ab | Close file
2018-12-17T22:53:58.216211549Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:53:58.228455067Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:53:58.23084035Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:53:58.235440416Z 25 PC: 94e62 | Get default drive
2018-12-17T22:53:58.237439093Z 71 PC: 970dd | Get current directory
2018-12-17T22:53:58.242583321Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:53:58.24577757Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:53:58.248401749Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:53:58.250577288Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:53:58.252284093Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:54:13.164017458Z 0 PC: 0 | Program terminate
2018-12-17T22:54:14.519046029Z 0 PC: 0 | Program terminate
2018-12-17T22:54:14.622374526Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:54:14.627398453Z 41 PC: 94fae | Parse filename
2018-12-17T22:54:14.628867797Z 41 PC: 9502f | Parse filename
2018-12-17T22:54:14.630172258Z 41 PC: 9504c | Parse filename
2018-12-17T22:54:14.633053756Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:54:14.6342541Z 71 PC: 986f3 | Get current directory
2018-12-17T22:54:14.639620542Z 78 PC: 986fe | Find first file
2018-12-17T22:54:14.645690975Z 71 PC: 9856c | Get current directory
2018-12-17T22:54:14.647690227Z 73 PC: 97c09 | Release memory
2018-12-17T22:54:14.648746979Z 75 PC: 11821 | Execute program
2018-12-17T22:54:14.658356532Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:54:14.661978426Z 76 PC: 12a4b | Terminate with return code (Return code = '36')