Sample viewer

vx.netlux.org/Trojan.DOS.Schizo.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:57.315187795Z 53 PC: 13356 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:57.317493456Z 53 PC: 13356 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:57.319779717Z 53 PC: 13356 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:57.321019031Z 53 PC: 13356 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:57.322539752Z 53 PC: 13356 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:57.324345089Z 53 PC: 13356 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:57.325724038Z 53 PC: 13356 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:57.327175907Z 53 PC: 13356 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:57.329951879Z 53 PC: 13356 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:57.331518435Z 53 PC: 13356 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:57.333060218Z 53 PC: 13356 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:57.335583982Z 53 PC: 13356 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:57.33713865Z 53 PC: 13356 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:57.338726482Z 53 PC: 13356 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:57.340586064Z 53 PC: 13356 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:57.341782522Z 53 PC: 13356 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:57.342993653Z 53 PC: 13356 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:57.348848868Z 53 PC: 13356 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:57.350649866Z 37 PC: 1336b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:57.35298885Z 37 PC: 13373 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:57.355884396Z 37 PC: 1337b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:57.36096768Z 37 PC: 13383 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:57.362834114Z 68 PC: 136c8 | I/O control for devices (Set for = '')
2018-12-17T23:08:57.451365156Z 37 PC: 12d87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:57.459677879Z 37 PC: 13465 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:08:57.461184394Z 37 PC: 13465 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:08:57.462841095Z 37 PC: 13465 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:08:57.464970571Z 37 PC: 13465 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:57.466440386Z 37 PC: 13465 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:57.468003565Z 37 PC: 13465 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:08:57.470727278Z 37 PC: 13465 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:08:57.472415448Z 37 PC: 13465 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:08:57.473732852Z 37 PC: 13465 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:08:57.475771991Z 37 PC: 13465 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:08:57.478332208Z 37 PC: 13465 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:08:57.47955028Z 37 PC: 13465 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:08:57.481087387Z 37 PC: 13465 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:08:57.482408947Z 37 PC: 13465 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:08:57.483598183Z 37 PC: 13465 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:08:57.484767982Z 37 PC: 13465 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:08:57.485821092Z 37 PC: 13465 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:08:57.487006972Z 37 PC: 13465 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:08:57.488179447Z 76 PC: 134a4 | Terminate with return code (Return code = '0')