Sample viewer

vx.netlux.org/Trojan.DOS.Vasil

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:43.886772602Z 53 PC: 131ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:43.888695443Z 53 PC: 131ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:43.889761336Z 53 PC: 131ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:43.890767482Z 53 PC: 131ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:43.892046522Z 53 PC: 131ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:43.893618894Z 53 PC: 131ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:43.895061272Z 53 PC: 131ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:43.896458454Z 53 PC: 131ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:43.897845163Z 53 PC: 131ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:43.898939048Z 53 PC: 131ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:43.900030569Z 53 PC: 131ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:43.909152854Z 53 PC: 131ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:43.910735023Z 53 PC: 131ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:43.912417539Z 53 PC: 131ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:43.914344513Z 53 PC: 131ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:43.91600346Z 53 PC: 131ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:43.917592447Z 53 PC: 131ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:43.919627758Z 53 PC: 131ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:43.92872255Z 53 PC: 131ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:43.930162819Z 37 PC: 131ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:43.932126161Z 37 PC: 13207 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:43.934185989Z 37 PC: 1320f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:43.936551341Z 37 PC: 13217 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:43.93775532Z 68 PC: 13875 | I/O control for devices (Set for = '+�e���&�>|')
2018-12-17T22:56:44.067899261Z 64 PC: 13608 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:56:44.070600968Z 37 PC: 13341 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:44.071837489Z 37 PC: 13341 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:44.073045321Z 37 PC: 13341 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:44.074897762Z 37 PC: 13341 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:44.076284787Z 37 PC: 13341 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:44.077536099Z 37 PC: 13341 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:44.079200488Z 37 PC: 13341 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:44.080423714Z 37 PC: 13341 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:44.08161862Z 37 PC: 13341 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:44.082991513Z 37 PC: 13341 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:44.084120721Z 37 PC: 13341 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:44.085080139Z 37 PC: 13341 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:44.086255558Z 37 PC: 13341 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:44.087544977Z 37 PC: 13341 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:44.088656353Z 37 PC: 13341 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:44.089983894Z 37 PC: 13341 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:44.090999391Z 37 PC: 13341 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:44.09203161Z 37 PC: 13341 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:44.093027131Z 37 PC: 13341 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:44.095070772Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.096984645Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.098878701Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.10141703Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.103271706Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.105504585Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.108186847Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.110694586Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.113122405Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.117314555Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.119862578Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.122046936Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.124618335Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.126560382Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.128539997Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.131081454Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.133042081Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.134987766Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.137483762Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.139381339Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.141241856Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.143969611Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.146054625Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.148016902Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.150481755Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.152489399Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.155107226Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.157819966Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.159744493Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.161631281Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.16421811Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.16622014Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.168063038Z 6 PC: 133c8 | Direct console I/O
2018-12-17T22:56:44.172076964Z 76 PC: 13380 | Terminate with return code (Return code = '200')