Sample viewer

vx.netlux.org/Trojan.DOS.Shark.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:45.403766497Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:09:45.409305256Z 41 PC: 94fae | Parse filename
2018-12-17T23:09:45.412770853Z 41 PC: 9502f | Parse filename
2018-12-17T23:09:45.414622615Z 41 PC: 9504c | Parse filename
2018-12-17T23:09:45.41764449Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T23:09:45.422066145Z 71 PC: 986f3 | Get current directory
2018-12-17T23:09:45.425490847Z 78 PC: 986fe | Find first file
2018-12-17T23:09:45.436052191Z 71 PC: 986f3 | Get current directory
2018-12-17T23:09:45.439171517Z 78 PC: 986fe | Find first file
2018-12-17T23:09:45.449083205Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T23:09:45.45377935Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:09:45.455466594Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:45.456437761Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:45.45808289Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.461057996Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.46270598Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.463821014Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.465625579Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.466890667Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.467929935Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.468878546Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.470287119Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.471287696Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.472258757Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.474637672Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.475967222Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.477263449Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.479225527Z 62 PC: 122ab | Close file
2018-12-17T23:09:45.481310356Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T23:09:45.482356434Z 56 PC: 94df9 | Get or set country info
2018-12-17T23:09:45.484668462Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:09:45.489394855Z 25 PC: 94e62 | Get default drive
2018-12-17T23:09:45.491157972Z 71 PC: 970dd | Get current directory
2018-12-17T23:09:45.495457406Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:09:45.498619274Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T23:09:45.500646807Z 93 PC: 94f20 | File sharing functions
2018-12-17T23:09:45.502850083Z 93 PC: 94f27 | File sharing functions
2018-12-17T23:09:45.50449006Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T23:10:00.451675441Z 0 PC: 0 | Program terminate
2018-12-17T23:10:01.806528797Z 0 PC: 0 | Program terminate
2018-12-17T23:10:01.909063616Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:10:01.916268728Z 41 PC: 94fae | Parse filename
2018-12-17T23:10:01.918398141Z 41 PC: 9502f | Parse filename
2018-12-17T23:10:01.920167875Z 41 PC: 9504c | Parse filename
2018-12-17T23:10:01.925023535Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T23:10:01.926790624Z 71 PC: 986f3 | Get current directory
2018-12-17T23:10:01.934447799Z 78 PC: 986fe | Find first file
2018-12-17T23:10:01.944559155Z 71 PC: 9856c | Get current directory
2018-12-17T23:10:01.947862385Z 73 PC: 97c09 | Release memory
2018-12-17T23:10:01.949551596Z 75 PC: 11821 | Execute program
2018-12-17T23:10:01.965492328Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T23:10:01.975961158Z 76 PC: 12a4b | Terminate with return code (Return code = '36')