Sample viewer

vx.netlux.org/Trojan.DOS.Hamara.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:25.529604956Z 48 PC: 1f99c | Get DOS version
2018-12-17T22:01:25.531533379Z 74 PC: 1f9ec | Reallocate memory
2018-12-17T22:01:25.53363254Z 48 PC: 1fa50 | Get DOS version
2018-12-17T22:01:25.535869113Z 53 PC: 1fa58 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:25.537441355Z 37 PC: 1fa6a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:25.539075851Z 53 PC: 22442 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:25.540630611Z 37 PC: 22452 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:25.542094669Z 53 PC: 22457 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:25.543431104Z 37 PC: 22467 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:25.544869464Z 53 PC: 20196 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:25.54682511Z 53 PC: 20196 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:25.548058287Z 53 PC: 20196 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:25.549280458Z 53 PC: 20196 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:25.551128111Z 53 PC: 20196 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:25.552336667Z 53 PC: 20196 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:25.553480564Z 53 PC: 20196 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:25.555480822Z 53 PC: 20196 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:25.556863925Z 53 PC: 20196 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:25.55829347Z 53 PC: 20196 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:25.560680645Z 53 PC: 20196 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:25.562097379Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:25.563410909Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:25.565508259Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:25.566819255Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:25.568037633Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:25.56981519Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:25.570865982Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:25.571874182Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:25.574465116Z 37 PC: 201cc | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:25.575973009Z 37 PC: 201d1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:25.577733748Z 68 PC: 1fafb | I/O control for devices (Set for = '�')
2018-12-17T22:01:25.580001009Z 68 PC: 1fafb | I/O control for devices (Set for = '+t���^[Z�W�@�;6D#r;�rt ��+���E��D��6D# �_�PSQRW�������Ë�3ɋ���Y����E����u���|��]����+�_ZY[X�V���\�^Ë6@#�<t�<u8\�t+t���+t����3��PSQR�')
2018-12-17T22:01:25.581660857Z 68 PC: 1fafb | I/O control for devices (Set for = '                                   ')
2018-12-17T22:01:25.583296837Z 68 PC: 1fafb | I/O control for devices (Set for = '                                 ')
2018-12-17T22:01:25.585874631Z 68 PC: 1fafb | I/O control for devices (Set for = '                                 ')
2018-12-17T22:01:25.587951203Z 53 PC: 1d288 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:25.5893902Z 53 PC: 1d295 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:25.592324364Z 53 PC: 1d2a2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:25.59351886Z 37 PC: 1d2b7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:25.594758379Z 37 PC: 1d2bf | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:25.597090359Z 37 PC: 1d2c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:25.598275165Z 53 PC: 1dd46 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:01:25.599336113Z 53 PC: 1dd53 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:01:25.603470789Z 53 PC: 1dd62 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:01:25.604746765Z 37 PC: 1dd6f | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:01:25.60615066Z 53 PC: 1dd76 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:01:25.60891456Z 37 PC: 1dd83 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:01:25.610234411Z 53 PC: 1dd8f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:01:25.615119948Z 48 PC: 1de51 | Get DOS version
2018-12-17T22:01:25.618055016Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:01:25.619962723Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:01:25.621614918Z 68 PC: 1d1fe | I/O control for devices (Set for = ' ----' '----5')
2018-12-17T22:01:25.623668862Z 68 PC: 1d1fe | I/O control for devices (Set for = '')
2018-12-17T22:01:25.6252684Z 51 PC: 1d21c | Get or set Ctrl-Break
2018-12-17T22:01:25.62998963Z 51 PC: 1d228 | Get or set Ctrl-Break
2018-12-17T22:01:25.631906141Z 72 PC: 17966 | Allocate memory
2018-12-17T22:01:25.634146201Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:01:25.635842961Z 72 PC: 17966 | Allocate memory
2018-12-17T22:01:25.639724187Z 37 PC: 18e11 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:01:25.646037978Z 73 PC: 17966 | Release memory
2018-12-17T22:01:25.648540458Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:01:25.651310219Z 51 PC: 1d233 | Get or set Ctrl-Break
2018-12-17T22:01:25.652465353Z 37 PC: 1d4b5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:25.653856454Z 37 PC: 1d4bf | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:25.65616229Z 37 PC: 1d4c9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:25.657586784Z 53 PC: 1b710 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:01:25.659004369Z 53 PC: 1b71d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:01:25.661209207Z 53 PC: 1b72a | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:01:25.662938878Z 37 PC: 1b745 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:01:25.664302156Z 53 PC: 1b74d | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:01:25.666462244Z 37 PC: 1b75a | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:01:25.668132742Z 53 PC: 1b761 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:01:25.669560199Z 37 PC: 1b76e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:01:25.671660189Z 37 PC: 1b778 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:01:25.673349221Z 37 PC: 1b783 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:01:25.674866904Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:25.676958842Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:25.678290259Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:25.679711575Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:25.681322066Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:25.683489688Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:25.684874961Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:25.686266346Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:25.688632665Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:25.689703164Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:25.691450789Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:25.695462534Z 37 PC: 22476 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:25.698633031Z 37 PC: 1fbac | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:25.702366778Z 41 PC: 1f893 | Parse filename
2018-12-17T22:01:25.704340591Z 41 PC: 1f895 | Parse filename
2018-12-17T22:01:25.705908252Z 41 PC: 1f89a | Parse filename
2018-12-17T22:01:25.708180389Z 75 PC: 1f8b0 | Execute program
2018-12-17T22:01:25.728099484Z 80 PC: 27399 | Set current PSP
2018-12-17T22:01:25.729141225Z 48 PC: 2739e | Get DOS version
2018-12-17T22:01:25.73205197Z 99 PC: 2db80 | Get DBCS lead byte table pointer
2018-12-17T22:01:25.735742642Z 101 PC: 27424 | Get extended country info
2018-12-17T22:01:25.736933113Z 99 PC: 2742a | Get DBCS lead byte table pointer
2018-12-17T22:01:25.738563347Z 74 PC: 2748c | Reallocate memory
2018-12-17T22:01:25.750251623Z 25 PC: 274c3 | Get default drive
2018-12-17T22:01:25.751340179Z 37 PC: 26f83 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:01:25.753189788Z 37 PC: 26f8a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:25.754864647Z 37 PC: 26f91 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:25.759522806Z 74 PC: 2612c | Reallocate memory
2018-12-17T22:01:25.762253518Z 72 PC: 2616d | Allocate memory
2018-12-17T22:01:25.764093477Z 72 PC: 261a5 | Allocate memory
2018-12-17T22:01:25.766011781Z 72 PC: 261ad | Allocate memory