Sample viewer

vx.netlux.org/Trojan.DOS.UCF.based

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:11.480784009Z 2 PC: 12ac6 | Character output (Char = '9d')
2018-12-17T22:55:11.483593297Z 2 PC: 12ac6 | Character output (Char = 'e2')
2018-12-17T22:55:11.492045755Z 2 PC: 12ac6 | Character output (Char = 'ae')
2018-12-17T22:55:11.494805032Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:11.497586073Z 2 PC: 12ac6 | Character output (Char = 'a6')
2018-12-17T22:55:11.50067392Z 2 PC: 12ac6 | Character output (Char = 'e3')
2018-12-17T22:55:11.503339293Z 2 PC: 12ac6 | Character output (Char = 'e2')
2018-12-17T22:55:11.50574254Z 2 PC: 12ac6 | Character output (Char = 'aa')
2018-12-17T22:55:11.508812895Z 2 PC: 12ac6 | Character output (Char = 'a8')
2018-12-17T22:55:11.511259406Z 2 PC: 12ac6 | Character output (Char = 'a9')
2018-12-17T22:55:11.513647342Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:11.516600488Z 2 PC: 12ac6 | Character output (Char = 'e2')
2018-12-17T22:55:11.523879419Z 2 PC: 12ac6 | Character output (Char = 'e0')
2018-12-17T22:55:11.526519663Z 2 PC: 12ac6 | Character output (Char = 'ae')
2018-12-17T22:55:11.52910615Z 2 PC: 12ac6 | Character output (Char = 'ef')
2018-12-17T22:55:11.531841011Z 2 PC: 12ac6 | Character output (Char = 'ad')
2018-12-17T22:55:11.534146242Z 2 PC: 12ac6 | Character output (Char = 'e1')
2018-12-17T22:55:11.536417519Z 2 PC: 12ac6 | Character output (Char = 'aa')
2018-12-17T22:55:11.550600346Z 2 PC: 12ac6 | Character output (Char = 'a8')
2018-12-17T22:55:11.553630292Z 2 PC: 12ac6 | Character output (Char = 'a9')
2018-12-17T22:55:11.55657157Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:11.560399377Z 2 PC: 12ac6 | Character output (Char = 'a2')
2018-12-17T22:55:11.579161578Z 2 PC: 12ac6 | Character output (Char = 'a8')
2018-12-17T22:55:11.582673451Z 2 PC: 12ac6 | Character output (Char = 'e0')
2018-12-17T22:55:11.586406039Z 2 PC: 12ac6 | Character output (Char = 'e3')
2018-12-17T22:55:11.58903046Z 2 PC: 12ac6 | Character output (Char = 'e1')
2018-12-17T22:55:11.59155835Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:11.594325378Z 2 PC: 12ac6 | Character output (Char = 'a8')
2018-12-17T22:55:11.608285597Z 2 PC: 12ac6 | Character output (Char = 'a7')
2018-12-17T22:55:11.61057416Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:11.612875474Z 2 PC: 12ac6 | Character output (Char = '91')
2018-12-17T22:55:11.616147752Z 2 PC: 12ac6 | Character output (Char = 'eb')
2018-12-17T22:55:11.619320336Z 2 PC: 12ac6 | Character output (Char = 'aa')
2018-12-17T22:55:11.62259562Z 2 PC: 12ac6 | Character output (Char = 'e2')
2018-12-17T22:55:11.625249017Z 2 PC: 12ac6 | Character output (Char = 'eb')
2018-12-17T22:55:11.639017446Z 2 PC: 12ac6 | Character output (Char = 'a2')
2018-12-17T22:55:11.642427437Z 2 PC: 12ac6 | Character output (Char = 'aa')
2018-12-17T22:55:11.645178617Z 2 PC: 12ac6 | Character output (Char = 'a0')
2018-12-17T22:55:11.648201492Z 2 PC: 12ac6 | Character output (Char = 'e0')
2018-12-17T22:55:11.650679147Z 2 PC: 12ac6 | Character output (Char = 'a0')
2018-12-17T22:55:11.653232127Z 2 PC: 12ac6 | Character output (Char = '0d')
2018-12-17T22:55:11.664373715Z 2 PC: 12ac6 | Character output (Char = '0a')
2018-12-17T22:55:12.017615004Z 2 PC: 12ac6 | Character output (Char = '80')
2018-12-17T22:55:12.020608898Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.024168336Z 2 PC: 12ac6 | Character output (Char = 'e1')
2018-12-17T22:55:12.0273113Z 2 PC: 12ac6 | Character output (Char = 'a5')
2018-12-17T22:55:12.030087892Z 2 PC: 12ac6 | Character output (Char = 'a9')
2018-12-17T22:55:12.032514749Z 2 PC: 12ac6 | Character output (Char = 'e7')
2018-12-17T22:55:12.035288533Z 2 PC: 12ac6 | Character output (Char = 'a0')
2018-12-17T22:55:12.037848356Z 2 PC: 12ac6 | Character output (Char = 'e1')
2018-12-17T22:55:12.040368516Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.042906399Z 2 PC: 12ac6 | Character output (Char = 'ef')
2018-12-17T22:55:12.046346979Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.048854528Z 2 PC: 12ac6 | Character output (Char = 'e3')
2018-12-17T22:55:12.051404265Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.054511655Z 2 PC: 12ac6 | Character output (Char = 'a2')
2018-12-17T22:55:12.057052168Z 2 PC: 12ac6 | Character output (Char = 'a0')
2018-12-17T22:55:12.061051824Z 2 PC: 12ac6 | Character output (Char = 'e1')
2018-12-17T22:55:12.064751789Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.067190197Z 2 PC: 12ac6 | Character output (Char = 'a2')
2018-12-17T22:55:12.069650061Z 2 PC: 12ac6 | Character output (Char = 'e1')
2018-12-17T22:55:12.072647387Z 2 PC: 12ac6 | Character output (Char = 'a5')
2018-12-17T22:55:12.0759609Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.07824193Z 2 PC: 12ac6 | Character output (Char = 'e3')
2018-12-17T22:55:12.080422462Z 2 PC: 12ac6 | Character output (Char = 'ad')
2018-12-17T22:55:12.082983947Z 2 PC: 12ac6 | Character output (Char = 'a8')
2018-12-17T22:55:12.085329956Z 2 PC: 12ac6 | Character output (Char = 'e7')
2018-12-17T22:55:12.087777184Z 2 PC: 12ac6 | Character output (Char = 'e2')
2018-12-17T22:55:12.091012028Z 2 PC: 12ac6 | Character output (Char = 'ae')
2018-12-17T22:55:12.093610481Z 2 PC: 12ac6 | Character output (Char = 'a6')
2018-12-17T22:55:12.096181648Z 2 PC: 12ac6 | Character output (Char = 'e3')
2018-12-17T22:55:12.099523977Z 2 PC: 12ac6 | Character output (Char = '20')
2018-12-17T22:55:12.102206009Z 2 PC: 12ac6 | Character output (Char = '95')
2018-12-17T22:55:12.106300292Z 2 PC: 12ac6 | Character output (Char = 'a0')
2018-12-17T22:55:12.109907006Z 2 PC: 12ac6 | Character output (Char = '2d')
2018-12-17T22:55:12.112916206Z 2 PC: 12ac6 | Character output (Char = '95')
2018-12-17T22:55:12.115902426Z 2 PC: 12ac6 | Character output (Char = 'a0')
2018-12-17T22:55:12.119398912Z 2 PC: 12ac6 | Character output (Char = '0d')
2018-12-17T22:55:12.121889299Z 2 PC: 12ac6 | Character output (Char = '0a')
2018-12-17T22:55:12.126843851Z 76 PC: 12ab2 | Terminate with return code (Return code = '0')