Sample viewer

vx.netlux.org/Trojan.DOS.Virri.l

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:44.544069149Z 48 PC: 19442 | Get DOS version
2018-12-17T23:05:44.547003185Z 74 PC: 19492 | Reallocate memory
2018-12-17T23:05:44.549882098Z 48 PC: 1921c | Get DOS version
2018-12-17T23:05:44.551421693Z 53 PC: 19224 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:44.553035527Z 37 PC: 19236 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:44.555372281Z 53 PC: 1baa2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:05:44.556847455Z 37 PC: 1bab2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:05:44.558555257Z 53 PC: 1bab7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:05:44.560795268Z 37 PC: 1bac7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:05:44.567293056Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:05:44.570268721Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:05:44.57223055Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:05:44.573970301Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:05:44.575882006Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:05:44.578388729Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:05:44.579914108Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:05:44.581379593Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:05:44.583571475Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:05:44.584938054Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:05:44.586691351Z 53 PC: 197f6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:05:44.590081666Z 37 PC: 19825 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:05:44.592060917Z 37 PC: 19825 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:05:44.593376781Z 37 PC: 19825 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:05:44.595824895Z 37 PC: 19825 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:05:44.599400167Z 37 PC: 19825 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:05:44.601309227Z 37 PC: 19825 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:05:44.603433671Z 37 PC: 19825 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:05:44.604677581Z 37 PC: 19825 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:05:44.605870343Z 37 PC: 1982c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:05:44.607323736Z 37 PC: 19831 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:05:44.611465744Z 68 PC: 192c7 | I/O control for devices (Set for = '+�! �u [��^]�')
2018-12-17T23:05:44.613372139Z 68 PC: 192c7 | I/O control for devices (Set for = ' Overflow#')
2018-12-17T23:05:44.616271621Z 68 PC: 192c7 | I/O control for devices (Set for = ' �t���ꡚ')
2018-12-17T23:05:44.618881117Z 68 PC: 192c7 | I/O control for devices (Set for = '��')
2018-12-17T23:05:44.62225452Z 68 PC: 192c7 | I/O control for devices (Set for = '��')
2018-12-17T23:05:44.624757176Z 53 PC: 16d18 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:44.629381932Z 53 PC: 16d25 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:05:44.631226931Z 53 PC: 16d32 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:44.633137203Z 37 PC: 16d47 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:44.636077111Z 37 PC: 16d4f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:05:44.637801183Z 37 PC: 16d57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:44.640188161Z 53 PC: 17290 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:05:44.642488516Z 53 PC: 1729d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:05:44.644037489Z 53 PC: 172ac | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:44.645819269Z 37 PC: 172b9 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:05:44.648089738Z 53 PC: 172c0 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:44.649642558Z 37 PC: 172cd | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:05:44.651133031Z 53 PC: 172d9 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:05:44.656993841Z 48 PC: 1739b | Get DOS version
2018-12-17T23:05:44.658971379Z 74 PC: 188c1 | Reallocate memory
2018-12-17T23:05:44.662457555Z 74 PC: 188c1 | Reallocate memory
2018-12-17T23:05:44.666152251Z 68 PC: 16c8e | I/O control for devices (Set for = 'no programms souch as SpIDer would help you')
2018-12-17T23:05:44.667925295Z 68 PC: 16c8e | I/O control for devices (Set for = '')
2018-12-17T23:05:44.669826259Z 51 PC: 16cac | Get or set Ctrl-Break
2018-12-17T23:05:44.67118783Z 51 PC: 16cb8 | Get or set Ctrl-Break
2018-12-17T23:05:44.674188773Z 72 PC: 18440 | Allocate memory
2018-12-17T23:05:44.678199163Z 74 PC: 188c1 | Reallocate memory
2018-12-17T23:05:44.680241183Z 72 PC: 18440 | Allocate memory
2018-12-17T23:05:44.69105206Z 61 PC: 13aba | Open file (Filename = 'C:\WINSTART.BAT')
2018-12-17T23:05:44.703675306Z 60 PC: 1397f | Create or truncate file
2018-12-17T23:05:45.387156975Z 62 PC: 1571b | Close file
2018-12-17T23:05:45.39033987Z 61 PC: 13aba | Open file (Filename = 'C:\WINSTART.BAT')
2018-12-17T23:05:45.397534107Z 68 PC: 13a13 | I/O control for devices (Set for = 'ustWorm /noinfect/')
2018-12-17T23:05:45.402165115Z 66 PC: 154bd | Move file pointer
2018-12-17T23:05:45.405983695Z 64 PC: 1570a | Write file or device (Write 16 bytes on handle 5)
2018-12-17T23:05:45.417134532Z 66 PC: 154bd | Move file pointer
2018-12-17T23:05:45.419008015Z 62 PC: 1571b | Close file
2018-12-17T23:05:45.430362504Z 73 PC: 18440 | Release memory
2018-12-17T23:05:45.433186233Z 74 PC: 188c1 | Reallocate memory
2018-12-17T23:05:45.435390679Z 51 PC: 16cc3 | Get or set Ctrl-Break
2018-12-17T23:05:45.437686816Z 37 PC: 16f45 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:45.439645209Z 37 PC: 16f4f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:05:45.44119903Z 37 PC: 16f59 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:45.443587461Z 53 PC: 157b0 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:45.445574428Z 53 PC: 157bd | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:05:45.447371086Z 53 PC: 157ca | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:45.449385293Z 37 PC: 157e5 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:05:45.454805484Z 53 PC: 157ed | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:05:45.456482989Z 37 PC: 157fa | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:45.458112934Z 53 PC: 15801 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:05:45.461010331Z 37 PC: 1580e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:45.462664522Z 37 PC: 15818 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:05:45.464201722Z 37 PC: 15823 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:05:45.466742049Z 37 PC: 19841 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:05:45.468130339Z 37 PC: 19841 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:05:45.469492601Z 37 PC: 19841 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:05:45.47193859Z 37 PC: 19841 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:05:45.473296553Z 37 PC: 19841 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:05:45.474680305Z 37 PC: 19841 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:05:45.476846228Z 37 PC: 19841 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:05:45.478475361Z 37 PC: 19841 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:05:45.479882096Z 37 PC: 19841 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:05:45.482547177Z 37 PC: 19841 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:05:45.483965213Z 37 PC: 19841 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:05:45.485390463Z 37 PC: 1bad6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:05:45.487853534Z 37 PC: 19378 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:45.49038783Z 41 PC: 190bb | Parse filename
2018-12-17T23:05:45.492219914Z 41 PC: 190bd | Parse filename
2018-12-17T23:05:45.495107885Z 41 PC: 190c2 | Parse filename
2018-12-17T23:05:45.504074284Z 75 PC: 190d8 | Execute program
2018-12-17T23:05:45.530697734Z 80 PC: 1f559 | Set current PSP
2018-12-17T23:05:45.531784027Z 48 PC: 1f55e | Get DOS version
2018-12-17T23:05:45.535090875Z 99 PC: 25d40 | Get DBCS lead byte table pointer
2018-12-17T23:05:45.537918201Z 101 PC: 1f5e4 | Get extended country info
2018-12-17T23:05:45.539619791Z 99 PC: 1f5ea | Get DBCS lead byte table pointer
2018-12-17T23:05:45.54149673Z 74 PC: 1f64c | Reallocate memory
2018-12-17T23:05:45.543269803Z 25 PC: 1f683 | Get default drive
2018-12-17T23:05:45.54497007Z 37 PC: 1f143 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:05:45.547140932Z 37 PC: 1f14a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:05:45.548594015Z 37 PC: 1f151 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:45.553443102Z 74 PC: 1e2ec | Reallocate memory
2018-12-17T23:05:45.556524105Z 72 PC: 1e32d | Allocate memory
2018-12-17T23:05:45.558591442Z 72 PC: 1e365 | Allocate memory
2018-12-17T23:05:45.560742026Z 72 PC: 1e36d | Allocate memory