Sample viewer

vx.netlux.org/Trojan.DOS.1648

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:15:57.050080325Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:15:57.051341846Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:15:57.053312891Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:15:57.054770691Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:15:57.05612671Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:57.058239701Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:15:57.060203473Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:15:57.062033923Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:15:57.064293941Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:15:57.065963459Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:15:57.067526627Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:15:57.06992733Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:15:57.071549979Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:15:57.073074575Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:15:57.074929021Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:15:57.0768813Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:15:57.078120029Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:15:57.079276332Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:15:57.084540296Z 37 PC: 12bab | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:15:57.086339147Z 37 PC: 12bb3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:15:57.08811214Z 37 PC: 12bbb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:57.09076728Z 37 PC: 12bc3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:15:57.095372897Z 68 PC: 12f08 | I/O control for devices (Set for = '')
2018-12-17T23:15:57.138139011Z 64 PC: 1300b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:15:57.14067638Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:15:57.142116097Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:15:57.143751491Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:15:57.145593273Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:15:57.146984077Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:57.14824674Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:15:57.151197476Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:15:57.152778107Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:15:57.154324183Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:15:57.156612083Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:15:57.158346994Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:15:57.159888652Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:15:57.161434748Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:15:57.163359606Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:15:57.164822556Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:15:57.16629311Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:15:57.168401533Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:15:57.169561654Z 37 PC: 12ca5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:15:57.17080483Z 76 PC: 12ce4 | Terminate with return code (Return code = '0')