Sample viewer

vx.netlux.org/Trojan.DOS.EatFlu.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:41.471731546Z 48 PC: 12a4b | Get DOS version
2018-12-17T22:01:41.473260245Z 53 PC: 12b83 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:41.474604092Z 53 PC: 12b90 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:41.476391867Z 53 PC: 12b9d | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:41.478028032Z 53 PC: 12baa | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:41.479619438Z 37 PC: 12bbe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:41.481260628Z 74 PC: 12af3 | Reallocate memory
2018-12-17T22:01:41.483947057Z 68 PC: 138a0 | I/O control for devices (Set for = '�{')
2018-12-17T22:01:41.485755875Z 68 PC: 138a0 | I/O control for devices (Set for = '� ��')
2018-12-17T22:01:41.487649141Z 59 PC: 1377b | Change current directory
2018-12-17T22:01:41.492018545Z 255 PC: 12c96 | UNKNOWN!
2018-12-17T22:01:41.492782864Z 42 PC: 13069 | Get date 0x13069: mov word ptr [si], cx
0x1306b: mov word ptr [si + 2], dx
0x1306e: pop si
0x1306f: pop bp
0x13070: ret
0x13071: push bp
0x13072: mov bp, sp
0x13074: push si
0x13075: mov si, word ptr [bp + 4]
0x13078: mov ah, 0x2c
0x1307a: int 0x21
0x1307c: mov word ptr [si], cx
0x1307e: mov word ptr [si + 2], dx
0x13081: pop si
0x13082: pop bp
0x13083: ret
0x13084: push bp
0x13085: mov bp, sp
0x13087: mov ax, word ptr [bp + 4]
0x1308a: mov word ptr [0x1abe], 0
2018-12-17T22:01:41.494777505Z 44 PC: 1307c | Get time 0x1307c: mov word ptr [si], cx
0x1307e: mov word ptr [si + 2], dx
0x13081: pop si
0x13082: pop bp
0x13083: ret
0x13084: push bp
0x13085: mov bp, sp
0x13087: mov ax, word ptr [bp + 4]
0x1308a: mov word ptr [0x1abe], 0
0x13090: mov word ptr [0x1abc], ax
0x13093: pop bp
0x13094: ret
0x13095: mov cx, word ptr [0x1abe]
0x13099: mov bx, word ptr [0x1abc]
0x1309d: mov dx, 0x15a
0x130a0: mov ax, 0x4e35
0x130a3: call 0x13f5b
0x130a6: add ax, 1
0x130a9: adc dx, 0
0x130ac: mov word ptr [0x1abe], dx
2018-12-17T22:01:41.498023304Z 47 PC: 137a2 | Get disk transfer address
2018-12-17T22:01:41.499300295Z 26 PC: 137ab | Set disk transfer address
2018-12-17T22:01:41.500245871Z 78 PC: 137b5 | Find first file
2018-12-17T22:01:41.50576722Z 26 PC: 137be | Set disk transfer address
2018-12-17T22:01:41.50800083Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.513993901Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.514933707Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.516433946Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.518762398Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.519851288Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.540701254Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.541718006Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.542737717Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.545997524Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.547071092Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.558263384Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.559736121Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.561210103Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.563618629Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.565708556Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.5717212Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.572645622Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.574219248Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.5765211Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.577605277Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.588767191Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.58993864Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.591020467Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.59398188Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.596062677Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.607296546Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.609532685Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.610681061Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.613175866Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.615423186Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.629622531Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.631092498Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.633234897Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.636110594Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.637886325Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.645299197Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.647046913Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.648524823Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.652091307Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.65478175Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.666203366Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.667707879Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.672094577Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.675060647Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.677150929Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.690792565Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.692069312Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.693266882Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.696568676Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.698350355Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.704424871Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.706692711Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.708122025Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.712879256Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.716042912Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.727859905Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.72900512Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.731119079Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.733657388Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.734860932Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.746448166Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.747706593Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.748875049Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.752460288Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.754076318Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.764920011Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.767230291Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.768315081Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.770830164Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.772901245Z 86 PC: 12d9e | Rename file
2018-12-17T22:01:41.78675315Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.787925255Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.790050147Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.792386228Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.793629622Z 47 PC: 137a2 | Get disk transfer address
2018-12-17T22:01:41.795705479Z 26 PC: 137ab | Set disk transfer address
2018-12-17T22:01:41.79745081Z 78 PC: 137b5 | Find first file
2018-12-17T22:01:41.80351012Z 26 PC: 137be | Set disk transfer address
2018-12-17T22:01:41.805794026Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.807513612Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.808887693Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.812997339Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.814567341Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.815964438Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.817337526Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.821022596Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.822468258Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.823789138Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.825943802Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.828329079Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.829425613Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.83643126Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.837839033Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.842689507Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.846546103Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.848014053Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.850663916Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.854037972Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.855453224Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.857473797Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.859210981Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.86171148Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.863522323Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.865633643Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.867107363Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.869826292Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.871985318Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.873645265Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.874958292Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.878378174Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.880002193Z 47 PC: 137d5 | Get disk transfer address
2018-12-17T22:01:41.881574626Z 26 PC: 137de | Set disk transfer address
2018-12-17T22:01:41.883562588Z 79 PC: 137e2 | Find next file
2018-12-17T22:01:41.88601142Z 26 PC: 137eb | Set disk transfer address
2018-12-17T22:01:41.887724293Z 37 PC: 12bca | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:41.889857882Z 37 PC: 12bd5 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:41.891506612Z 37 PC: 12be0 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:41.892823149Z 37 PC: 12beb | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:41.895549692Z 76 PC: 12b74 | Terminate with return code (Return code = '0')