Sample viewer

vx.netlux.org/Trojan.DOS.Mywec

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:28.042184154Z 48 PC: 1726c | Get DOS version
2018-12-17T22:59:28.044583263Z 74 PC: 172bc | Reallocate memory
2018-12-17T22:59:28.046710671Z 48 PC: 17320 | Get DOS version
2018-12-17T22:59:28.048153352Z 53 PC: 17328 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:28.05470217Z 37 PC: 1733a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:28.057324548Z 53 PC: 19f82 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:28.059481753Z 37 PC: 19f92 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:59:28.062444511Z 53 PC: 19f97 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:28.063674673Z 37 PC: 19fa7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:28.064754953Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:28.066564524Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:28.068657207Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:28.070305575Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:28.071790455Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:28.07370365Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:28.075370373Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:28.076968386Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:28.079199208Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:28.080819073Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:28.082423508Z 53 PC: 17cd6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:59:28.0844942Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:59:28.086146274Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:59:28.087660951Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:59:28.090157573Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:59:28.091381614Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:59:28.092625992Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:59:28.094935192Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:59:28.096144665Z 37 PC: 17d05 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:59:28.097335554Z 37 PC: 17d0c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:59:28.099710727Z 37 PC: 17d11 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:59:28.101840319Z 68 PC: 173cb | I/O control for devices (Set for = 'X��� � �u&�6������<t�<t+t���+t����3��4NPW�D���+�9Eu �t_X�� �>��=u ��+E�;�t�>�;>�t ��E��=t��>��PSQVW��F�6��6��6����:���>h')
2018-12-17T22:59:28.103794552Z 68 PC: 173cb | I/O control for devices
2018-12-17T22:59:28.106516388Z 68 PC: 173cb | I/O control for devices (Set for = 'nd.com')
2018-12-17T22:59:28.1085076Z 68 PC: 173cb | I/O control for devices (Set for = 'm Files\ICQ\*.*$')
2018-12-17T22:59:28.110792474Z 68 PC: 173cb | I/O control for devices (Set for = 'm Files\ICQ\*.*$')
2018-12-17T22:59:28.114431844Z 53 PC: 14aea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:28.116086674Z 53 PC: 14af7 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:59:28.117644511Z 53 PC: 14b04 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:28.119619934Z 37 PC: 14b19 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:59:28.121569689Z 37 PC: 14b21 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:59:28.12359762Z 37 PC: 14b29 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:28.12609326Z 53 PC: 155a8 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:59:28.127399895Z 53 PC: 155b5 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:59:28.132248388Z 53 PC: 155c4 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:59:28.133826674Z 37 PC: 155d1 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:59:28.135348384Z 53 PC: 155d8 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:59:28.137440175Z 37 PC: 155e5 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:59:28.13913496Z 53 PC: 155f1 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:59:28.145146338Z 48 PC: 156b3 | Get DOS version
2018-12-17T22:59:28.147684678Z 68 PC: 14a60 | I/O control for devices (Set for = 'utlook Express\*.**')
2018-12-17T22:59:28.149378411Z 68 PC: 14a60 | I/O control for devices (Set for = '')
2018-12-17T22:59:28.151075611Z 51 PC: 14a7e | Get or set Ctrl-Break
2018-12-17T22:59:28.154179865Z 51 PC: 14a8a | Get or set Ctrl-Break