Sample viewer

vx.netlux.org/Trojan.DOS.Mike

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:20.510679264Z 53 PC: 1385a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:20.513044501Z 53 PC: 1385a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:20.514485684Z 53 PC: 1385a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:20.515915773Z 53 PC: 1385a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:20.518752795Z 53 PC: 1385a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:20.520350232Z 53 PC: 1385a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:20.521741897Z 53 PC: 1385a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:20.524433447Z 53 PC: 1385a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:20.525951808Z 53 PC: 1385a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:20.527782767Z 53 PC: 1385a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:20.529210761Z 53 PC: 1385a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:20.530878809Z 53 PC: 1385a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:20.532259418Z 53 PC: 1385a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:20.533607531Z 53 PC: 1385a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:20.535749139Z 53 PC: 1385a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:20.537041164Z 53 PC: 1385a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:20.538316808Z 53 PC: 1385a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:20.548682399Z 53 PC: 1385a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:20.550195997Z 53 PC: 1385a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:20.551834879Z 37 PC: 1386f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:20.554277665Z 37 PC: 13877 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:20.555762402Z 37 PC: 1387f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:20.557227873Z 37 PC: 13887 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:20.560340253Z 68 PC: 14101 | I/O control for devices (Set for = '3�5�;�=�Ìَ��.��tD���')
2018-12-17T22:57:20.60275422Z 37 PC: 13141 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:20.60523197Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:20.607403264Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:20.609083855Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:20.610610314Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:20.612341426Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:20.614552611Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:20.615925803Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:20.617349592Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:20.619820083Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:20.621225057Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:20.622652415Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:20.625673582Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:20.627057857Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:20.628467013Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:20.630738721Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:20.632174799Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:20.633768641Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:20.636224331Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:20.637426627Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:20.638586848Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:20.640658176Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:20.642128645Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:20.643559137Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:20.647482875Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:20.649033556Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:20.65060327Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:20.65271545Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:20.654031137Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:20.66216978Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:20.663859962Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:20.666038724Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:20.667475518Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:20.668899934Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:20.671567063Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:20.672988801Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:20.674498976Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:20.676955699Z 53 PC: 137d8 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:20.678338627Z 37 PC: 137e1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:20.680409494Z 41 PC: 1378f | Parse filename
2018-12-17T22:57:20.682845065Z 41 PC: 1379d | Parse filename
2018-12-17T22:57:20.684711795Z 75 PC: 137a8 | Execute program
2018-12-17T22:57:20.714606035Z 80 PC: 17cf9 | Set current PSP
2018-12-17T22:57:20.716506256Z 48 PC: 17cfe | Get DOS version
2018-12-17T22:57:20.718130945Z 99 PC: 1e4e0 | Get DBCS lead byte table pointer
2018-12-17T22:57:20.720971081Z 101 PC: 17d84 | Get extended country info
2018-12-17T22:57:20.723418991Z 99 PC: 17d8a | Get DBCS lead byte table pointer
2018-12-17T22:57:20.724962567Z 74 PC: 17dec | Reallocate memory
2018-12-17T22:57:20.726717952Z 25 PC: 17e23 | Get default drive
2018-12-17T22:57:20.728734812Z 37 PC: 178e3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:57:20.730075102Z 37 PC: 178ea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:20.731478098Z 37 PC: 178f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:20.737483727Z 74 PC: 16a8c | Reallocate memory
2018-12-17T22:57:20.739308697Z 72 PC: 16acd | Allocate memory
2018-12-17T22:57:20.74111736Z 72 PC: 16b05 | Allocate memory
2018-12-17T22:57:20.743755477Z 72 PC: 16b0d | Allocate memory