Sample viewer

vx.netlux.org/Trojan.DOS.Venta

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:57.079044629Z 53 PC: 1396a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:57.081010899Z 53 PC: 1396a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:57.082194562Z 53 PC: 1396a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:57.083316888Z 53 PC: 1396a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:57.085449686Z 53 PC: 1396a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:57.086938355Z 53 PC: 1396a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:57.08833204Z 53 PC: 1396a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:57.089736389Z 53 PC: 1396a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:57.091582852Z 53 PC: 1396a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:57.092616573Z 53 PC: 1396a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:57.094163617Z 53 PC: 1396a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:57.095667379Z 53 PC: 1396a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:57.096735057Z 53 PC: 1396a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:57.097888423Z 53 PC: 1396a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:57.099769838Z 53 PC: 1396a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:57.101007561Z 53 PC: 1396a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:57.102072633Z 53 PC: 1396a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:57.104346597Z 53 PC: 1396a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:57.105429772Z 53 PC: 1396a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:57.106504027Z 37 PC: 1397f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:57.108167229Z 37 PC: 13987 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:57.109175507Z 37 PC: 1398f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:57.110104848Z 37 PC: 13997 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:57.112200167Z 68 PC: 14410 | I/O control for devices (Set for = 'w��ÿ7��')
2018-12-17T23:06:57.186293023Z 37 PC: 131d1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:57.187693051Z 42 PC: 13757 | Get date 0x13757: xor ah, ah
0x13759: les di, ptr [bp + 6]
0x1375c: stosw word ptr es:[di], ax
0x1375d: mov al, dl
0x1375f: les di, ptr [bp + 0xa]
0x13762: stosw word ptr es:[di], ax
0x13763: mov al, dh
0x13765: les di, ptr [bp + 0xe]
0x13768: stosw word ptr es:[di], ax
0x13769: xchg ax, cx
0x1376a: les di, ptr [bp + 0x12]
0x1376d: stosw word ptr es:[di], ax
0x1376e: pop bp
0x1376f: retf 0x10
0x13772: push bp
0x13773: mov bp, sp
0x13775: mov cx, word ptr [bp + 0xa]
0x13778: mov dh, byte ptr [bp + 8]
0x1377b: mov dl, byte ptr [bp + 6]
0x1377e: mov ah, 0x2b
2018-12-17T23:06:57.190367386Z 25 PC: 140dd | Get default drive
2018-12-17T23:06:57.191296449Z 71 PC: 140f0 | Get current directory
2018-12-17T23:06:57.194449552Z 48 PC: 14050 | Get DOS version
2018-12-17T23:06:57.196769137Z 53 PC: 138da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:57.198033077Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:57.199083068Z 53 PC: 138da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:57.201069381Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:57.202043811Z 53 PC: 138da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:57.203017263Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:57.20439735Z 53 PC: 138da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:57.205437093Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:57.206403882Z 53 PC: 138da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:57.207903713Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:57.208914114Z 53 PC: 138da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:57.209887231Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:57.211304717Z 53 PC: 138da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:57.212350314Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:57.213324571Z 53 PC: 138da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:57.214860751Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:57.215808214Z 53 PC: 138da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:57.216752629Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:57.218213278Z 53 PC: 138da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:57.219221532Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:57.220170278Z 53 PC: 138da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:57.221633064Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:57.222590169Z 53 PC: 138da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:57.22355415Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:57.224887821Z 53 PC: 138da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:57.225906045Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:57.226841141Z 53 PC: 138da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:57.228197585Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:57.229180417Z 53 PC: 138da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:57.230161289Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:57.231526086Z 53 PC: 138da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:57.232556593Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:57.233478008Z 53 PC: 138da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:57.234694139Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:57.235657789Z 53 PC: 138da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:57.236621479Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:57.23799973Z 53 PC: 138da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:57.23909889Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:57.241395229Z 41 PC: 13891 | Parse filename
2018-12-17T23:06:57.243090167Z 41 PC: 1389f | Parse filename
2018-12-17T23:06:57.244278071Z 75 PC: 138aa | Execute program
2018-12-17T23:06:57.251442257Z 53 PC: 138da | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:57.252912044Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:57.253935129Z 53 PC: 138da | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:57.254953357Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:57.256421311Z 53 PC: 138da | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:57.257489007Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:57.25870386Z 53 PC: 138da | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:57.260302376Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:57.261375149Z 53 PC: 138da | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:57.262348945Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:57.263740912Z 53 PC: 138da | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:57.264788159Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:57.265747007Z 53 PC: 138da | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:57.267111781Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:57.269200996Z 53 PC: 138da | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:57.270562591Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:57.272108273Z 53 PC: 138da | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:57.273783279Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:57.275023863Z 53 PC: 138da | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:57.277119833Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:57.278169576Z 53 PC: 138da | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:57.279425148Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:57.281114741Z 53 PC: 138da | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:57.282321781Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:57.28355273Z 53 PC: 138da | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:57.285229202Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:57.286202719Z 53 PC: 138da | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:57.287180455Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:57.288591699Z 53 PC: 138da | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:57.289912714Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:57.291108705Z 53 PC: 138da | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:57.292503777Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:57.293324921Z 53 PC: 138da | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:57.294105161Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:57.294930675Z 53 PC: 138da | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:57.296012937Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:57.296775717Z 53 PC: 138da | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:57.297716796Z 37 PC: 138e3 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:57.298896361Z 60 PC: 143f4 | Create or truncate file
2018-12-17T23:06:57.890696419Z 68 PC: 14410 | I/O control for devices (Set for = 'w��ÿ7��')
2018-12-17T23:06:57.892733551Z 64 PC: 13d63 | Write file or device (Write 29 bytes on handle 5)
2018-12-17T23:06:57.900941847Z 62 PC: 13da2 | Close file