Sample viewer

vx.netlux.org/Trojan.DOS.Filemaker

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:31.45902935Z 48 PC: 18a7c | Get DOS version
2018-12-17T22:02:31.461302804Z 74 PC: 18acc | Reallocate memory
2018-12-17T22:02:31.463346497Z 48 PC: 18b30 | Get DOS version
2018-12-17T22:02:31.464678895Z 53 PC: 18b38 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:31.467300075Z 37 PC: 18b4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:31.468926497Z 53 PC: 1b1d2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:31.470330642Z 37 PC: 1b1e2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:02:31.472471863Z 53 PC: 1b1e7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:31.474220997Z 37 PC: 1b1f7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:02:31.475563599Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:31.478045994Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:31.479564061Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:31.480910157Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:31.483205478Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:31.484606081Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:31.486051063Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:31.487764268Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:31.493956703Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:31.494896312Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:31.49571603Z 53 PC: 18f26 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:02:31.497280682Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:02:31.49910062Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:02:31.50081969Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:02:31.502752157Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:02:31.503739427Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:02:31.50465885Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:02:31.506667504Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:02:31.508086924Z 37 PC: 18f55 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:02:31.509503245Z 37 PC: 18f5c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:02:31.511619791Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:02:31.513200389Z 68 PC: 18bdb | I/O control for devices (Set for = '�t��D�����U��V�^3�3��P')
2018-12-17T22:02:31.514751432Z 68 PC: 18bdb | I/O control for devices (Set for = ' "$&(*,.02468:<>@BDFHJLNPRTVXZ\^`bdfhjlnprtvxz|~����������������������������������������������������������������')
2018-12-17T22:02:31.517004443Z 68 PC: 18bdb | I/O control for devices (Set for = '��')
2018-12-17T22:02:31.518309558Z 68 PC: 18bdb | I/O control for devices (Set for = '�l�|��\�P')
2018-12-17T22:02:31.519690593Z 68 PC: 18bdb | I/O control for devices (Set for = '�l�|��\�P')
2018-12-17T22:02:31.522466895Z 53 PC: 1609c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:31.523653662Z 53 PC: 160a9 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:02:31.525776987Z 53 PC: 160b6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:31.527932626Z 37 PC: 160cb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:02:31.529366452Z 37 PC: 160d3 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:02:31.530769292Z 37 PC: 160db | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:31.53724787Z 53 PC: 16b5a | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:02:31.538409456Z 53 PC: 16b67 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:02:31.539747368Z 53 PC: 16b76 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:02:31.541540907Z 37 PC: 16b83 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:02:31.542697789Z 53 PC: 16b8a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:02:31.544537383Z 37 PC: 16b97 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:02:31.549714814Z 53 PC: 16ba3 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:02:31.554423522Z 48 PC: 16c65 | Get DOS version
2018-12-17T22:02:31.555967986Z 68 PC: 16012 | I/O control for devices (Set for = 'LPT1LPT2LPT3LPT4')
2018-12-17T22:02:31.558234309Z 68 PC: 16012 | I/O control for devices (Set for = '')
2018-12-17T22:02:31.559795476Z 51 PC: 16030 | Get or set Ctrl-Break
2018-12-17T22:02:31.56078717Z 51 PC: 1603c | Get or set Ctrl-Break
2018-12-17T22:02:31.563514838Z 37 PC: 14ab1 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:02:31.570161784Z 71 PC: 13f6a | Get current directory
2018-12-17T22:02:31.581167057Z 26 PC: 12e31 | Set disk transfer address
2018-12-17T22:02:31.58950504Z 78 PC: 12e38 | Find first file
2018-12-17T22:02:31.602544435Z 61 PC: 1453c | Open file (Filename = 'C:\WINDOWS\TEXT.TXT')
2018-12-17T22:02:31.609964849Z 60 PC: 14401 | Create or truncate file
2018-12-17T22:02:31.961924308Z 62 PC: 1436f | Close file
2018-12-17T22:02:31.963935482Z 61 PC: 1453c | Open file (Filename = 'C:\WINDOWS\TEXT.TXT')
2018-12-17T22:02:31.969451663Z 68 PC: 14495 | I/O control for devices (Set for = '')
2018-12-17T22:02:31.972688218Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.974869264Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.97712125Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.979423122Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.98165758Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.983800437Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.986755157Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.989120038Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.991760856Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.994856121Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.996860085Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:31.9990513Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.001522757Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.003437685Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.009897809Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.012602976Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.014802173Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.017112493Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.020133974Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.021669322Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.023186335Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.025495263Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.02701045Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.028547761Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.035493125Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.037466694Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.039072413Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.041026251Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.042534104Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.044365863Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.046720348Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.048083409Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.049524062Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.051492924Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.053535374Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.055530584Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.05817316Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.060069414Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.061928712Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.06436038Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.067024963Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.068839115Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.070568472Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.071852199Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.073148251Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.074878821Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.076352897Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.078372814Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.080539281Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.082536562Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.084452782Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.088040786Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.090082476Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.092009758Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.094298143Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.09624194Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.098404036Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.100849403Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.102710638Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.104571246Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.107113962Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.109072263Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.111071117Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.113655661Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.115641838Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.117645958Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.11964169Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.121511359Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.124986676Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.127163136Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.129011804Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.130960045Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.133289115Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.13519863Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.137631313Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.139480319Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.141232001Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.143495307Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.144874392Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.146378849Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.149244145Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.15120147Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.152963388Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.155571266Z 62 PC: 1436f | Close file
2018-12-17T22:02:32.157944172Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.159639758Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.161991856Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.163934911Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.165884989Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.168300087Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.170215628Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.172120692Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.174773421Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.176747985Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.178886144Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.18182555Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.183593618Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.186010274Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.19525824Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.197433477Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.199901184Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.205154942Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.207354707Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.210615357Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.213628815Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.21827379Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.220786917Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.223342779Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.225487465Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.228638918Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.230597404Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.232828331Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.235622309Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.2380678Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.240095538Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.243669088Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.245979418Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.248266146Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.251273539Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.253587928Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.255852255Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.259159314Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.261446726Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.263710605Z 6 PC: 15fe3 | Direct console I/O
2018-12-17T22:02:32.268224074Z 12 PC: 1608c | Flush input buffer and input