Sample viewer

vx.netlux.org/Trojan.DOS.Byte3t

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:47.748094187Z 48 PC: 1688c | Get DOS version
2018-12-17T22:57:47.750313495Z 74 PC: 168dc | Reallocate memory
2018-12-17T22:57:47.752160158Z 48 PC: 16940 | Get DOS version
2018-12-17T22:57:47.753533469Z 53 PC: 16948 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:47.755369379Z 37 PC: 1695a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:47.757180147Z 68 PC: 169eb | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T22:57:47.759127305Z 68 PC: 169eb | I/O control for devices
2018-12-17T22:57:47.761054588Z 68 PC: 169eb | I/O control for devices
2018-12-17T22:57:47.763367628Z 68 PC: 169eb | I/O control for devices
2018-12-17T22:57:47.765157564Z 68 PC: 169eb | I/O control for devices
2018-12-17T22:57:47.766585597Z 53 PC: 14b3a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:47.767999564Z 53 PC: 14b47 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:57:47.769063259Z 53 PC: 14b54 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:47.770025205Z 37 PC: 14b69 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:47.771469265Z 37 PC: 14b71 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:57:47.772621198Z 37 PC: 14b79 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:47.77402882Z 53 PC: 155f8 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:57:47.775644905Z 53 PC: 15605 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:57:47.776571707Z 53 PC: 15614 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:57:47.777458527Z 37 PC: 15621 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:57:47.77880524Z 53 PC: 15628 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:57:47.780097195Z 37 PC: 15635 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:57:47.786658711Z 53 PC: 15641 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:57:47.791674133Z 48 PC: 15703 | Get DOS version
2018-12-17T22:57:47.793272232Z 68 PC: 14ab0 | I/O control for devices (Set for = 'e21.bat�:')
2018-12-17T22:57:47.795098361Z 68 PC: 14ab0 | I/O control for devices (Set for = '')
2018-12-17T22:57:47.797143801Z 51 PC: 14ace | Get or set Ctrl-Break
2018-12-17T22:57:47.798287518Z 51 PC: 14ada | Get or set Ctrl-Break
2018-12-17T22:57:47.80289195Z 61 PC: 134e0 | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:57:47.811388457Z 68 PC: 13439 | I/O control for devices (Set for = 'c:\autoexec.bat >> c:\byte21.bat�:')
2018-12-17T22:57:47.814464965Z 64 PC: 13302 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:57:48.150452508Z 64 PC: 13302 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:57:48.168516184Z 64 PC: 13302 | Write file or device (Write 320 bytes on handle 5)
2018-12-17T22:57:48.172524652Z 66 PC: 130b5 | Move file pointer
2018-12-17T22:57:48.173984155Z 62 PC: 13313 | Close file
2018-12-17T22:57:48.184616566Z 61 PC: 134e0 | Open file (Filename = 'C:\AUTOEXEC.BON')
2018-12-17T22:57:48.191778053Z 60 PC: 133a5 | Create or truncate file
2018-12-17T22:57:48.204090099Z 62 PC: 13313 | Close file
2018-12-17T22:57:48.206440994Z 61 PC: 134e0 | Open file (Filename = 'C:\AUTOEXEC.BON')
2018-12-17T22:57:48.215150727Z 68 PC: 13439 | I/O control for devices (Set for = 'c:\autoexec.bat >> c:\byte21.bat�:')
2018-12-17T22:57:48.218350858Z 64 PC: 13302 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:57:48.221027719Z 64 PC: 13302 | Write file or device (Write 182 bytes on handle 5)
2018-12-17T22:57:48.22605138Z 66 PC: 130b5 | Move file pointer
2018-12-17T22:57:48.227839204Z 62 PC: 13313 | Close file
2018-12-17T22:57:48.244822551Z 37 PC: 158d3 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:57:48.24726065Z 53 PC: 158da | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:57:48.248498167Z 37 PC: 158e7 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:57:48.249652375Z 37 PC: 158f2 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:57:48.251127941Z 37 PC: 158fd | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:57:48.25290506Z 51 PC: 14ae5 | Get or set Ctrl-Break
2018-12-17T22:57:48.253850424Z 37 PC: 14d67 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:48.254979629Z 37 PC: 14d71 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:57:48.258795547Z 37 PC: 14d7b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:48.26020366Z 37 PC: 16a9c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:48.261733814Z 76 PC: 16a85 | Terminate with return code (Return code = '0')