Sample viewer

vx.netlux.org/Trojan.DOS.Bill'N'Ted

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:54.895180031Z 53 PC: 13352 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:54.898365089Z 53 PC: 13352 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:54.899855271Z 53 PC: 13352 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:54.901267616Z 53 PC: 13352 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:54.903739753Z 53 PC: 13352 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:54.905820635Z 53 PC: 13352 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:54.907229494Z 53 PC: 13352 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:54.908641859Z 53 PC: 13352 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:54.911741045Z 53 PC: 13352 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:54.913946862Z 53 PC: 13352 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:54.916688527Z 53 PC: 13352 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:54.919616301Z 53 PC: 13352 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:54.92314275Z 53 PC: 13352 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:54.925082075Z 53 PC: 13352 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:54.930593757Z 53 PC: 13352 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:54.932907938Z 53 PC: 13352 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:54.934741244Z 53 PC: 13352 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:54.938820403Z 53 PC: 13352 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:54.941439166Z 53 PC: 13352 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:54.94366492Z 37 PC: 13367 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:54.950335501Z 37 PC: 1336f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:54.953096912Z 37 PC: 13377 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:54.955014557Z 37 PC: 1337f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:54.958110317Z 68 PC: 136f1 | I/O control for devices (Set for = '')
2018-12-17T23:06:54.995949081Z 37 PC: 12d05 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:55.347709608Z 37 PC: 13466 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:55.35145541Z 37 PC: 13466 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:55.353695571Z 37 PC: 13466 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:55.355048965Z 37 PC: 13466 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:55.356606403Z 37 PC: 13466 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:55.358948827Z 37 PC: 13466 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:55.360560877Z 37 PC: 13466 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:55.361973202Z 37 PC: 13466 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:55.365138403Z 37 PC: 13466 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:55.36683387Z 37 PC: 13466 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:55.368470627Z 37 PC: 13466 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:55.370920473Z 37 PC: 13466 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:55.372965758Z 37 PC: 13466 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:55.374543454Z 37 PC: 13466 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:55.376559995Z 37 PC: 13466 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:55.378282844Z 37 PC: 13466 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:55.380323861Z 37 PC: 13466 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:55.382774117Z 37 PC: 13466 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:55.384160082Z 37 PC: 13466 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:55.385561016Z 76 PC: 134a5 | Terminate with return code (Return code = '0')