Sample viewer

vx.netlux.org/Trojan.DOS.Jackel

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:45.236969934Z 53 PC: 1336a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.239339506Z 53 PC: 1336a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:45.241351997Z 53 PC: 1336a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:45.243097687Z 53 PC: 1336a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.244808241Z 53 PC: 1336a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.247215384Z 53 PC: 1336a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.24888418Z 53 PC: 1336a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:45.254277113Z 53 PC: 1336a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:45.258194093Z 53 PC: 1336a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:45.259664937Z 53 PC: 1336a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:45.261015545Z 53 PC: 1336a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:45.270077342Z 53 PC: 1336a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:45.271756026Z 53 PC: 1336a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:45.273130018Z 53 PC: 1336a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:45.275335402Z 53 PC: 1336a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:45.276682323Z 53 PC: 1336a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:45.277925789Z 53 PC: 1336a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:45.280160498Z 53 PC: 1336a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.281891761Z 53 PC: 1336a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:45.284974694Z 37 PC: 1337f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.286796236Z 37 PC: 13387 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.289895359Z 37 PC: 1338f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.291774621Z 37 PC: 13397 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.294107654Z 68 PC: 13a86 | I/O control for devices (Set for = '�%�')
2018-12-17T23:01:45.428929985Z 64 PC: 13788 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:01:45.431546782Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:45.433460448Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:45.436042549Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:45.437525947Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:45.438889208Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:45.441674011Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:45.443343067Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:01:45.445076304Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:01:45.447209252Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:01:45.449064578Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:01:45.450647132Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:01:45.452444629Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:01:45.454987327Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:01:45.456547969Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:01:45.45813437Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:01:45.460483173Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:01:45.46183891Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:01:45.463219094Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:01:45.465161333Z 37 PC: 134c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:45.466472156Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.469189582Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.472340062Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.474945758Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.477578375Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.481405055Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.483968813Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.487107731Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.490214148Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.492915343Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.495319361Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.49790551Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.501097658Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.503352535Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.505706879Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.509223255Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.516632117Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.520244945Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.523773966Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.526596089Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.529398074Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.533479844Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.5385975Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.541065597Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.544424439Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.547161612Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.549954921Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.554190148Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.559671056Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.562565325Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.565520297Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.568168313Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.570542123Z 6 PC: 13548 | Direct console I/O
2018-12-17T23:01:45.574666954Z 76 PC: 13500 | Terminate with return code (Return code = '200')