Sample viewer

vx.netlux.org/Trojan.DOS.Mylove.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:53.387892506Z 53 PC: 168da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:53.390295586Z 53 PC: 168da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:53.391628333Z 53 PC: 168da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:53.392732447Z 53 PC: 168da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:53.394890174Z 53 PC: 168da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:53.396035845Z 53 PC: 168da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:53.397152438Z 53 PC: 168da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:53.398923921Z 53 PC: 168da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:53.400498336Z 53 PC: 168da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:53.401991428Z 53 PC: 168da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:53.404058417Z 53 PC: 168da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:53.405656376Z 53 PC: 168da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:53.407254709Z 53 PC: 168da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:53.409131251Z 53 PC: 168da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:53.411390162Z 53 PC: 168da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:53.41282106Z 53 PC: 168da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:53.414265722Z 53 PC: 168da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:53.416241999Z 53 PC: 168da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:53.417603411Z 53 PC: 168da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:53.418962688Z 37 PC: 168ef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:53.420988759Z 37 PC: 168f7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:53.422966102Z 37 PC: 168ff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:53.424898876Z 37 PC: 16907 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:53.426798507Z 68 PC: 17ebe | I/O control for devices (Set for = '�t&�M� .85u.�M���s-� �t���t&;�.;u� It�����r ����u&}r2�&� G�q�')
2018-12-17T22:01:53.429439698Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:53.430560254Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:53.431773534Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:53.433511353Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:53.434566965Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:53.440325823Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:53.44194043Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:53.443347001Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:53.444408439Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:53.446205571Z 37 PC: 172c0 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:53.447660373Z 37 PC: 172c7 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:53.448951348Z 37 PC: 172ce | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:53.450722653Z 37 PC: 172d5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:53.522588694Z 37 PC: 16301 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:53.526936585Z 61 PC: 179f1 | Open file (Filename = 'EGAVGA.BGI')
2018-12-17T22:01:53.53806941Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:53.539378843Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:53.540639589Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:53.54296168Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:53.544218887Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:53.545514428Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:53.546692007Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:53.547756978Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:53.548810162Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:53.550042766Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:53.551238272Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:53.552078453Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:53.553592547Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:53.554799927Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:53.555919328Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:53.557570802Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:53.559228263Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:53.560154222Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:53.561291092Z 37 PC: 16a31 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:53.5677713Z 76 PC: 16a70 | Terminate with return code (Return code = '1')