Sample viewer

vx.netlux.org/Trojan.DOS.PatchConfig

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:33.338970859Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:33.341702475Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:33.343386501Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:33.345575156Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:33.347530912Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:33.349288557Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:33.350766345Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:33.35250344Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:33.358375551Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:33.363951804Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:33.366334323Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:33.368800961Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:33.370763751Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:33.37251319Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:33.374799578Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:33.376634668Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:33.378320398Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:33.38055572Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:33.382223566Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:33.383901751Z 37 PC: 12b7f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:33.385829525Z 37 PC: 12b87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:33.387544559Z 37 PC: 12b8f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:33.388739806Z 37 PC: 12b97 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:33.390460571Z 68 PC: 132f1 | I/O control for devices (Set for = '')
2018-12-17T23:06:33.396811892Z 61 PC: 132d5 | Open file (Filename = 'c:\config.sys')
2018-12-17T23:06:33.403830287Z 68 PC: 132f1 | I/O control for devices (Set for = '')
2018-12-17T23:06:33.405528099Z 66 PC: 13340 | Move file pointer
2018-12-17T23:06:33.408737884Z 66 PC: 13357 | Move file pointer
2018-12-17T23:06:33.41065067Z 63 PC: 13364 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:06:33.417758192Z 64 PC: 12f63 | Write file or device (Write 21 bytes on handle 5)
2018-12-17T23:06:33.421945595Z 62 PC: 12fa2 | Close file
2018-12-17T23:06:33.753654529Z 48 PC: 13233 | Get DOS version
2018-12-17T23:06:33.75609058Z 65 PC: 131ba | Delete file (Filename = 'A:\TEST.EXE')
2018-12-17T23:06:33.77636187Z 64 PC: 12f88 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:06:33.778932303Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:33.780563559Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:33.782908278Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:33.784756172Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:33.78663793Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:33.78870204Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:33.790839268Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:33.792555445Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:33.794657026Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:33.797022313Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:33.798815695Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:33.800572608Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:33.803034726Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:33.804452612Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:33.80594094Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:33.808321396Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:33.809847014Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:33.81129677Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:33.813618915Z 37 PC: 12cc1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:33.815326405Z 76 PC: 12d00 | Terminate with return code (Return code = '0')