Sample viewer

vx.netlux.org/Trojan.DOS.TagUtility

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:58.127899037Z 53 PC: 136db | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:58.129604071Z 53 PC: 136e8 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:58.131501416Z 53 PC: 136f5 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:58.1330468Z 53 PC: 13702 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:58.135253165Z 53 PC: 1370f | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:58.138413734Z 37 PC: 13722 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:58.139981069Z 37 PC: 1372a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:58.142824291Z 37 PC: 13732 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:58.148792936Z 68 PC: 13c9b | I/O control for devices (Set for = '')
2018-12-17T23:01:58.208083171Z 53 PC: 130af | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:58.209859929Z 37 PC: 130c2 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:58.213448092Z 60 PC: 13c83 | Create or truncate file
2018-12-17T23:01:58.219725326Z 60 PC: 13c83 | Create or truncate file
2018-12-17T23:01:58.229692133Z 37 PC: 1318d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:58.23169675Z 37 PC: 1377e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:58.233768793Z 37 PC: 13789 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:01:58.235142444Z 37 PC: 13794 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:58.237240436Z 37 PC: 1379f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:58.242111839Z 37 PC: 137aa | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:01:58.244449722Z 76 PC: 138ed | Terminate with return code (Return code = '0')