Sample viewer

vx.netlux.org/Trojan.DOS.Tbrain

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:20.837042447Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:20.838839372Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:20.840126632Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:20.841317068Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:20.843217896Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:20.844428382Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:20.845598162Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:20.848444684Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:20.849665371Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:20.851041878Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:20.852398009Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:20.854108961Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:20.855295491Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:20.856522911Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:20.858304373Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:20.866393691Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:20.868532865Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:20.870671605Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:20.873645226Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:20.874836794Z 37 PC: 12b4f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:20.876871325Z 37 PC: 12b57 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:20.878737685Z 37 PC: 12b5f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:20.879827169Z 37 PC: 12b67 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:20.882747991Z 68 PC: 13199 | I/O control for devices (Set for = 'P&�>�t�&&��')
2018-12-17T22:02:20.88458285Z 60 PC: 12ffd | Create or truncate file
2018-12-17T22:02:21.223594441Z 64 PC: 130d0 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:02:21.22951437Z 62 PC: 1304d | Close file
2018-12-17T22:02:21.237539288Z 64 PC: 12f58 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:02:21.239694655Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:21.242831818Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:21.244409498Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:02:21.245881012Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:21.248327368Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:21.249631327Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:21.251788092Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:21.252974893Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:21.254549773Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:21.255638035Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:21.256860481Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:21.259417155Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:21.260422786Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:21.261666721Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:21.263485005Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:21.264572467Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:21.265681358Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:21.277027388Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:02:21.279611629Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:02:21.2808131Z 76 PC: 12cd0 | Terminate with return code (Return code = '0')