Sample viewer

vx.netlux.org/Trojan.DOS.Inwin

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:04.514998632Z 48 PC: 12cc0 | Get DOS version
2018-12-17T23:02:04.517460535Z 74 PC: 12d1f | Reallocate memory
2018-12-17T23:02:04.519533484Z 48 PC: 12d84 | Get DOS version
2018-12-17T23:02:04.520844067Z 53 PC: 12d8c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:04.523392462Z 53 PC: 15432 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:04.524890799Z 37 PC: 15442 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:04.52647327Z 53 PC: 15447 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:04.528104499Z 37 PC: 15457 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:04.530040958Z 53 PC: 13048 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:04.531417308Z 53 PC: 13048 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:04.532710532Z 53 PC: 13048 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:04.536524707Z 53 PC: 13048 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:04.537732273Z 53 PC: 13048 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:04.538929593Z 53 PC: 13048 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:04.543966647Z 53 PC: 13048 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:04.544950074Z 53 PC: 13048 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:04.545918873Z 53 PC: 13048 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:04.547551438Z 53 PC: 13048 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:04.548962778Z 53 PC: 13048 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:02:04.55020576Z 37 PC: 13077 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:04.552009036Z 37 PC: 13077 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:04.553260504Z 37 PC: 13077 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:04.554421762Z 37 PC: 13077 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:04.555813967Z 37 PC: 13077 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:04.557172771Z 37 PC: 13077 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:04.558420003Z 37 PC: 13077 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:04.559828918Z 37 PC: 13077 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:04.561412771Z 37 PC: 1307e | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:04.562373487Z 37 PC: 13083 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:04.564121516Z 68 PC: 12e2c | I/O control for devices (Set for = 'G�M������Ã���.��W �F� �ێ���ӎÌF�!��PWVRQSU��؎���Ӌ��~G�M���4���Ŋ݃���.������t���p�v')
2018-12-17T23:02:04.565349913Z 68 PC: 12e2c | I/O control for devices
2018-12-17T23:02:04.566914881Z 68 PC: 12e2c | I/O control for devices (Set for = '&���')
2018-12-17T23:02:04.56873428Z 68 PC: 12e2c | I/O control for devices (Set for = '@����&H����Ë>')
2018-12-17T23:02:04.570626648Z 68 PC: 12e2c | I/O control for devices (Set for = '@����&H����Ë>')
2018-12-17T23:02:04.573444254Z 53 PC: 196b4 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:04.575260515Z 37 PC: 196ca | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:04.577487124Z 53 PC: 1754a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:04.578636564Z 53 PC: 17557 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:02:04.579777298Z 53 PC: 17564 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:04.581627719Z 37 PC: 17576 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:04.582823365Z 37 PC: 1757e | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:02:04.583960237Z 37 PC: 177f2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:04.589416588Z 74 PC: 187f9 | Reallocate memory
2018-12-17T23:02:04.590916036Z 74 PC: 187f9 | Reallocate memory
2018-12-17T23:02:04.594706923Z 68 PC: 17284 | I/O control for devices (Set for = '�]�]^N^b^h^�y�y�y�y�y�y�y�y�`�`�`Bata�a�a')
2018-12-17T23:02:04.596908791Z 68 PC: 17284 | I/O control for devices
2018-12-17T23:02:04.598578218Z 51 PC: 172a1 | Get or set Ctrl-Break
2018-12-17T23:02:04.599470141Z 51 PC: 172ad | Get or set Ctrl-Break
2018-12-17T23:02:04.610939065Z 74 PC: 187f9 | Reallocate memory
2018-12-17T23:02:04.612469562Z 51 PC: 172b8 | Get or set Ctrl-Break
2018-12-17T23:02:04.613432Z 37 PC: 175bc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:04.615139616Z 37 PC: 175c6 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:02:04.61621905Z 37 PC: 175d0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:04.617419563Z 37 PC: 13093 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:04.618813584Z 37 PC: 13093 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:04.623224616Z 37 PC: 13093 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:04.624791002Z 37 PC: 13093 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:04.62635268Z 37 PC: 13093 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:04.628002703Z 37 PC: 13093 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:04.629008657Z 37 PC: 13093 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:04.630077055Z 37 PC: 13093 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:04.632321147Z 37 PC: 13093 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:04.633709629Z 37 PC: 13093 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:04.63523354Z 37 PC: 13093 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:02:04.638078123Z 37 PC: 15466 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:04.639495636Z 37 PC: 12ef2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:04.641962165Z 41 PC: 196ff | Parse filename
2018-12-17T23:02:04.651918047Z 41 PC: 19701 | Parse filename
2018-12-17T23:02:04.654611282Z 41 PC: 19706 | Parse filename
2018-12-17T23:02:04.657150122Z 75 PC: 1971c | Execute program
2018-12-17T23:02:04.684623962Z 80 PC: 1cc19 | Set current PSP
2018-12-17T23:02:04.685686299Z 48 PC: 1cc1e | Get DOS version
2018-12-17T23:02:04.687492146Z 99 PC: 23400 | Get DBCS lead byte table pointer
2018-12-17T23:02:04.69131633Z 101 PC: 1cca4 | Get extended country info
2018-12-17T23:02:04.692913674Z 99 PC: 1ccaa | Get DBCS lead byte table pointer
2018-12-17T23:02:04.694603861Z 74 PC: 1cd0c | Reallocate memory
2018-12-17T23:02:04.696645842Z 25 PC: 1cd43 | Get default drive
2018-12-17T23:02:04.699390001Z 37 PC: 1c803 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:02:04.700998833Z 37 PC: 1c80a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:04.702844521Z 37 PC: 1c811 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:04.708525977Z 74 PC: 1b9ac | Reallocate memory
2018-12-17T23:02:04.710744609Z 72 PC: 1b9ed | Allocate memory
2018-12-17T23:02:04.713148258Z 72 PC: 1ba25 | Allocate memory
2018-12-17T23:02:04.715719819Z 72 PC: 1ba2d | Allocate memory