Sample viewer

vx.netlux.org/Trojan.DOS.FCK

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:50.431566417Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:50.434713542Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:50.437727296Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:50.441341719Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:50.443048967Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:50.446102546Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:50.44938746Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:50.451125787Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:50.462217322Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:50.463759059Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:50.474911098Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:50.476846015Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:50.47858326Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:50.480329822Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:50.482392138Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:50.486521358Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:50.488006469Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:50.489944281Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:50.491396771Z 53 PC: 12e52 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:50.492802292Z 37 PC: 12e67 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:50.495143582Z 37 PC: 12e6f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:50.496732198Z 37 PC: 12e77 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:50.498040627Z 37 PC: 12e7f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:50.499825551Z 68 PC: 131ef | I/O control for devices (Set for = '')
2018-12-17T23:09:50.503822253Z 14 PC: 13930 | Set default drive (Drive = 'C')
2018-12-17T23:09:50.505749435Z 25 PC: 13934 | Get default drive
2018-12-17T23:09:50.507575617Z 59 PC: 1399e | Change current directory
2018-12-17T23:09:50.515544944Z 26 PC: 12d35 | Set disk transfer address
2018-12-17T23:09:50.516903587Z 78 PC: 12d41 | Find first file
2018-12-17T23:09:50.527324903Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.867993994Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.869795811Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:50.874489382Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.888032334Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.889480385Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:50.89395237Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.907807178Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.909929055Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:50.916532215Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.930075749Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.932446674Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:50.937830222Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.955192723Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.957906012Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:50.962829575Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.976159577Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.97880054Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:50.983811798Z 86 PC: 1389d | Rename file
2018-12-17T23:09:50.996030051Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:50.998496877Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.003564291Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.016042632Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.018861209Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.023557405Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.036169227Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.038697739Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.044685061Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.057164796Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.058888715Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.064364797Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.077180492Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.078942714Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.084185307Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.102910578Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.104343561Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.110401356Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.124962212Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.126615358Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.131309931Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.145614294Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.146826512Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.151526665Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.164615935Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.166170937Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.170777024Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.184612797Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.185985416Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.190735373Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.204531701Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.206631117Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.211807385Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.22980005Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.231177028Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.23572254Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.254555855Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.256288361Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.260801512Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.271600157Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.273525396Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.277384358Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.289835108Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.292131944Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.296844891Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.309764632Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.311950139Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.316459905Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.329955979Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.333987947Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.33860319Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.660027433Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.662432302Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.671451313Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.68925371Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.691514158Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.698834887Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.727498345Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.728730781Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.733686305Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.747089995Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.748696304Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.754374776Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.76672684Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.768350662Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.773200145Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.785799254Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.787290186Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.79419873Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.807134561Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.808330058Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.813473103Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.825910517Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.827188309Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.841013912Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.853111979Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.854361137Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.858747741Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.872399778Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.874290231Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.8790312Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.892203256Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.893843578Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.898332705Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.91156302Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.912999249Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.916566082Z 14 PC: 13930 | Set default drive (Drive = 'C')
2018-12-17T23:09:51.920060609Z 25 PC: 13934 | Get default drive
2018-12-17T23:09:51.921672298Z 59 PC: 1399e | Change current directory
2018-12-17T23:09:51.926236657Z 26 PC: 12d35 | Set disk transfer address
2018-12-17T23:09:51.928176873Z 78 PC: 12d41 | Find first file
2018-12-17T23:09:51.935428512Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.947153808Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.949521929Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.956968233Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.968095755Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.970703025Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.974816526Z 86 PC: 1389d | Rename file
2018-12-17T23:09:51.986261425Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:51.988160795Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:51.993275096Z 86 PC: 1389d | Rename file
2018-12-17T23:09:52.011151062Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:52.012699983Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:52.017172418Z 86 PC: 1389d | Rename file
2018-12-17T23:09:52.028324096Z 26 PC: 12d59 | Set disk transfer address
2018-12-17T23:09:52.029801593Z 79 PC: 12d5e | Find next file
2018-12-17T23:09:52.03320562Z 64 PC: 132f2 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:09:52.035417858Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:52.037316045Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:09:52.039045996Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:09:52.040572886Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:52.042482314Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:09:52.044157823Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:52.045762059Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:09:52.047547414Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:09:52.049967622Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:09:52.051575885Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:09:52.053168608Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:09:52.055310694Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:09:52.056595208Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:09:52.057880283Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:09:52.06027333Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:09:52.061564596Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:09:52.062967233Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:09:52.067604187Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:09:52.069013927Z 37 PC: 12f66 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:09:52.070399911Z 76 PC: 12fa5 | Terminate with return code (Return code = '0')