Sample viewer

vx.netlux.org/Trojan.DOS.Tornado_Patch

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:41.990721167Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:00:41.993207455Z 53 PC: 12bf2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:41.994352574Z 53 PC: 12bff | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:00:41.995533579Z 53 PC: 12c0c | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:00:41.997363516Z 53 PC: 12c19 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:00:41.998477728Z 37 PC: 12c2d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:41.999599926Z 74 PC: 12af7 | Reallocate memory
2018-12-17T23:00:42.001904531Z 68 PC: 13241 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T23:00:42.003659815Z 68 PC: 13241 | I/O control for devices (Set for = '')
2018-12-17T23:00:42.006833506Z 68 PC: 13241 | I/O control for devices (Set for = '')
2018-12-17T23:00:42.009025071Z 59 PC: 1312f | Change current directory
2018-12-17T23:00:42.014215864Z 64 PC: 13f18 | Write file or device (Write 28 bytes on handle 1)
2018-12-17T23:00:42.020199972Z 64 PC: 13f18 | Write file or device (Write 24 bytes on handle 1)
2018-12-17T23:00:42.027133381Z 64 PC: 13f18 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T23:00:42.033604876Z 47 PC: 137a8 | Get disk transfer address
2018-12-17T23:00:42.034740546Z 26 PC: 137b1 | Set disk transfer address
2018-12-17T23:00:42.036803269Z 78 PC: 137bb | Find first file
2018-12-17T23:00:42.043389706Z 26 PC: 137c4 | Set disk transfer address
2018-12-17T23:00:42.044674001Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.045661102Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.047092623Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.049788491Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.05107986Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.052854117Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.053877357Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.056330802Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.05809666Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.059058419Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.059968863Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.062867235Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.064082411Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.065065406Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.066398051Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.068787553Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.069984493Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.071644346Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.075821448Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.078505823Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.080424983Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.081856964Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.083170219Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.086094815Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.087454797Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.088746821Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.090328471Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.092838846Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.0941538Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.096108507Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.097201991Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.099700204Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.102079007Z 47 PC: 137db | Get disk transfer address
2018-12-17T23:00:42.1031863Z 26 PC: 137e4 | Set disk transfer address
2018-12-17T23:00:42.104254468Z 79 PC: 137e8 | Find next file
2018-12-17T23:00:42.113438141Z 26 PC: 137f1 | Set disk transfer address
2018-12-17T23:00:42.116749414Z 37 PC: 12c39 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:42.118093151Z 37 PC: 12c44 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:00:42.119978867Z 37 PC: 12c4f | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:00:42.121266805Z 37 PC: 12c5a | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:00:42.122612125Z 76 PC: 12be3 | Terminate with return code (Return code = '0')