Sample viewer

vx.netlux.org/Trojan.DOS.4212

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:38.096269661Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:00:38.098758205Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:38.101755007Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:00:38.103226293Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:00:38.105381002Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:00:38.106437445Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:38.107561439Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:00:38.110021844Z 68 PC: 13314 | I/O control for devices (Set for = 'h')
2018-12-17T22:00:38.112041052Z 68 PC: 13314 | I/O control for devices (Set for = 'h')
2018-12-17T22:00:38.113998241Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.483784232Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.48542267Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.486933412Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.488616087Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.490538439Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.492251478Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.494157535Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.496659442Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.498433618Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.50012813Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.50220359Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.503892656Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.505492776Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.507666418Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.509345899Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.511025587Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.513020199Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.514731789Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.516388034Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.518750486Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.520397946Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.522057921Z 28 PC: 1329e | Get allocation info for specified drive
2018-12-17T22:00:38.524447651Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:38.525354536Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:00:38.526239211Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:00:38.527671082Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:00:38.528864032Z 76 PC: 12b9c | Terminate with return code (Return code = '255')