Sample viewer

vx.netlux.org/Trojan.DOS.FakeTelnet

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:51.558652625Z 48 PC: 151e4 | Get DOS version
2018-12-17T22:00:51.577403538Z 51 PC: 1521a | Get or set Ctrl-Break
2018-12-17T22:00:51.578740816Z 51 PC: 15222 | Get or set Ctrl-Break
2018-12-17T22:00:51.594699606Z 51 PC: 15242 | Get or set Ctrl-Break
2018-12-17T22:00:51.843328179Z 53 PC: 153b0 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:00:51.845365079Z 53 PC: 153b7 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:00:51.846977864Z 37 PC: 153c4 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:00:51.848462244Z 37 PC: 153cb | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:00:51.851479187Z 37 PC: 15417 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:00:51.852603662Z 37 PC: 1541e | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:00:51.856723705Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.85845539Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.859933423Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.861485072Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.863430197Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.865768819Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.867231558Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.869238588Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.870711256Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.872245241Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.874673679Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.876148489Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.877642985Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.879806076Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.882849823Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.884337578Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.886095837Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.887944758Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.889128804Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.906763894Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.908879096Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.910990887Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.913255252Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.915373404Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.916855016Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.919255238Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.920570526Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.921838334Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.922973513Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.924374175Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.925560788Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.926693724Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.928661184Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.930338464Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.931865349Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.933925142Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.93541988Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.937023077Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.93913939Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.940487261Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.941907306Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.943890107Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.945391103Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.946774273Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.948765975Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.950303985Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.951724943Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.953744154Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.955252841Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.956634797Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.95886645Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.960615246Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.962151884Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.964419025Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.966629366Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.968052254Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.97056199Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.97239712Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.973968128Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.976415741Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.978064124Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.979493732Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.981649821Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.983159425Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.984578118Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.986661846Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.988686659Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.99016636Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.992112784Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.993667093Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:51.995120822Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:51.996909506Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:51.998594867Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.000043372Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.001846102Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.00350616Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.004931144Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.006870859Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.008490165Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.00970443Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.012015733Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.013547723Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.014977202Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.016618522Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.018375685Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.019824999Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.021572395Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.023429019Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.024853264Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.02656929Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.028352783Z 48 PC: 15574 | Get DOS version
2018-12-17T22:00:52.029700376Z 48 PC: 15582 | Get DOS version
2018-12-17T22:00:52.031345036Z 53 PC: 15590 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.037991785Z 53 PC: 144ca | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.039202055Z 53 PC: 144ca | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:00:52.040756571Z 53 PC: 144ca | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:00:52.042554727Z 53 PC: 144ca | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:00:52.043769414Z 53 PC: 144ca | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:00:52.044895697Z 53 PC: 144ca | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:52.046741462Z 53 PC: 144ca | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:00:52.047980822Z 53 PC: 144ca | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:00:52.049185291Z 53 PC: 144ca | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:00:52.051303818Z 53 PC: 144ca | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:00:52.052618538Z 53 PC: 144ca | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:00:52.054159092Z 53 PC: 144ca | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:00:52.057376308Z 53 PC: 144ca | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:00:52.058934059Z 53 PC: 144ca | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:00:52.060548696Z 53 PC: 144ca | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:00:52.062805806Z 53 PC: 144ca | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:00:52.064374481Z 53 PC: 144ca | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:00:52.065998141Z 53 PC: 144ca | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:00:52.068320708Z 53 PC: 144ca | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:00:52.070255567Z 37 PC: 144df | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.071614811Z 37 PC: 144e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:00:52.073426544Z 37 PC: 144ef | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:52.074618303Z 37 PC: 144f7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:00:52.076410084Z 68 PC: 14ecf | I/O control for devices (Set for = '��&�<')
2018-12-17T22:00:52.294794389Z 64 PC: 148e8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:00:52.296885377Z 37 PC: 14621 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:52.298345852Z 37 PC: 14621 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:00:52.30068108Z 37 PC: 14621 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:00:52.302137879Z 37 PC: 14621 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:00:52.30356786Z 37 PC: 14621 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:00:52.306007312Z 37 PC: 14621 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:52.307268909Z 37 PC: 14621 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:00:52.308693341Z 37 PC: 14621 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:00:52.310909537Z 37 PC: 14621 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:00:52.312496647Z 37 PC: 14621 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:00:52.313969638Z 37 PC: 14621 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:00:52.31708656Z 37 PC: 14621 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:00:52.318538414Z 37 PC: 14621 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:00:52.319924206Z 37 PC: 14621 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:00:52.322077477Z 37 PC: 14621 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:00:52.323431184Z 37 PC: 14621 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:00:52.324797561Z 37 PC: 14621 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:00:52.326663557Z 37 PC: 14621 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:00:52.327993426Z 37 PC: 14621 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:00:52.329425488Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.332732269Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.334971519Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.337205655Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.340230647Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.342639115Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.344842611Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.347713842Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.349925357Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.35212735Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.355153085Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.357580976Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.35975637Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.362751631Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.365168443Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.367405588Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.37032088Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.372382629Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.374654368Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.377623421Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.380079806Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.382400594Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.386175196Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.388526463Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.390839321Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.393841567Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.396171735Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.398428068Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.401509981Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.42179601Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.424163248Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.427520427Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.429746534Z 6 PC: 146a8 | Direct console I/O
2018-12-17T22:00:52.433588436Z 76 PC: 14660 | Terminate with return code (Return code = '200')