Sample viewer

vx.netlux.org/Trojan.DOS.VFat

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:52.036507835Z 48 PC: 140c0 | Get DOS version
2018-12-17T23:09:52.039623378Z 2 PC: 141a5 | Character output (Char = '50')
2018-12-17T23:09:52.042777451Z 2 PC: 141a5 | Character output (Char = '72')
2018-12-17T23:09:52.045507574Z 2 PC: 141a5 | Character output (Char = '6f')
2018-12-17T23:09:52.048678377Z 2 PC: 141a5 | Character output (Char = '67')
2018-12-17T23:09:52.051271984Z 2 PC: 141a5 | Character output (Char = '72')
2018-12-17T23:09:52.054140074Z 2 PC: 141a5 | Character output (Char = '61')
2018-12-17T23:09:52.057106881Z 2 PC: 141a5 | Character output (Char = '6d')
2018-12-17T23:09:52.060024625Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.062375148Z 2 PC: 141a5 | Character output (Char = '74')
2018-12-17T23:09:52.064733513Z 2 PC: 141a5 | Character output (Char = '6f')
2018-12-17T23:09:52.067765321Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.070138517Z 2 PC: 141a5 | Character output (Char = '76')
2018-12-17T23:09:52.072508732Z 2 PC: 141a5 | Character output (Char = '69')
2018-12-17T23:09:52.075603768Z 2 PC: 141a5 | Character output (Char = '65')
2018-12-17T23:09:52.078306345Z 2 PC: 141a5 | Character output (Char = '77')
2018-12-17T23:09:52.081427237Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.084824157Z 2 PC: 141a5 | Character output (Char = '46')
2018-12-17T23:09:52.087736589Z 2 PC: 141a5 | Character output (Char = '41')
2018-12-17T23:09:52.090561413Z 2 PC: 141a5 | Character output (Char = '54')
2018-12-17T23:09:52.094287148Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.096834555Z 2 PC: 141a5 | Character output (Char = '6f')
2018-12-17T23:09:52.099225817Z 2 PC: 141a5 | Character output (Char = '66')
2018-12-17T23:09:52.102877064Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.10543332Z 2 PC: 141a5 | Character output (Char = '61')
2018-12-17T23:09:52.108210303Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.111000682Z 2 PC: 141a5 | Character output (Char = '64')
2018-12-17T23:09:52.114182186Z 2 PC: 141a5 | Character output (Char = '65')
2018-12-17T23:09:52.11750044Z 2 PC: 141a5 | Character output (Char = '76')
2018-12-17T23:09:52.119920048Z 2 PC: 141a5 | Character output (Char = '69')
2018-12-17T23:09:52.123824429Z 2 PC: 141a5 | Character output (Char = '63')
2018-12-17T23:09:52.126293019Z 2 PC: 141a5 | Character output (Char = '65')
2018-12-17T23:09:52.128767265Z 2 PC: 141a5 | Character output (Char = '0d')
2018-12-17T23:09:52.132038653Z 2 PC: 141a5 | Character output (Char = '0a')
2018-12-17T23:09:52.136307622Z 2 PC: 141a5 | Character output (Char = '42')
2018-12-17T23:09:52.138683829Z 2 PC: 141a5 | Character output (Char = '79')
2018-12-17T23:09:52.143140179Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.150872621Z 2 PC: 141a5 | Character output (Char = '43')
2018-12-17T23:09:52.153171373Z 2 PC: 141a5 | Character output (Char = '61')
2018-12-17T23:09:52.162436245Z 2 PC: 141a5 | Character output (Char = '6c')
2018-12-17T23:09:52.168495956Z 2 PC: 141a5 | Character output (Char = '76')
2018-12-17T23:09:52.171157985Z 2 PC: 141a5 | Character output (Char = '69')
2018-12-17T23:09:52.17416509Z 2 PC: 141a5 | Character output (Char = '6e')
2018-12-17T23:09:52.177181775Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.180175048Z 2 PC: 141a5 | Character output (Char = '48')
2018-12-17T23:09:52.182987568Z 2 PC: 141a5 | Character output (Char = '73')
2018-12-17T23:09:52.185809391Z 2 PC: 141a5 | Character output (Char = '69')
2018-12-17T23:09:52.188187005Z 2 PC: 141a5 | Character output (Char = '61')
2018-12-17T23:09:52.190564785Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.193085381Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.195441285Z 2 PC: 141a5 | Character output (Char = '4d')
2018-12-17T23:09:52.199266395Z 2 PC: 141a5 | Character output (Char = '61')
2018-12-17T23:09:52.20268147Z 2 PC: 141a5 | Character output (Char = '79')
2018-12-17T23:09:52.205085994Z 2 PC: 141a5 | Character output (Char = '2c')
2018-12-17T23:09:52.207510121Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.210920998Z 2 PC: 141a5 | Character output (Char = '31')
2018-12-17T23:09:52.21337665Z 2 PC: 141a5 | Character output (Char = '39')
2018-12-17T23:09:52.215776196Z 2 PC: 141a5 | Character output (Char = '38')
2018-12-17T23:09:52.220543532Z 2 PC: 141a5 | Character output (Char = '35')
2018-12-17T23:09:52.223478293Z 2 PC: 141a5 | Character output (Char = '0d')
2018-12-17T23:09:52.226029516Z 2 PC: 141a5 | Character output (Char = '0a')
2018-12-17T23:09:52.240157462Z 2 PC: 141a5 | Character output (Char = '54')
2018-12-17T23:09:52.24209516Z 2 PC: 141a5 | Character output (Char = '6f')
2018-12-17T23:09:52.24393411Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.245985788Z 2 PC: 141a5 | Character output (Char = '75')
2018-12-17T23:09:52.248393701Z 2 PC: 141a5 | Character output (Char = '73')
2018-12-17T23:09:52.250727242Z 2 PC: 141a5 | Character output (Char = '65')
2018-12-17T23:09:52.252984145Z 2 PC: 141a5 | Character output (Char = '3a')
2018-12-17T23:09:52.256721594Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.259683019Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.2628672Z 2 PC: 141a5 | Character output (Char = '56')
2018-12-17T23:09:52.266375122Z 2 PC: 141a5 | Character output (Char = '66')
2018-12-17T23:09:52.269129408Z 2 PC: 141a5 | Character output (Char = '61')
2018-12-17T23:09:52.271866245Z 2 PC: 141a5 | Character output (Char = '74')
2018-12-17T23:09:52.276254493Z 2 PC: 141a5 | Character output (Char = '20')
2018-12-17T23:09:52.278992717Z 2 PC: 141a5 | Character output (Char = '64')
2018-12-17T23:09:52.281695454Z 2 PC: 141a5 | Character output (Char = '3a')
2018-12-17T23:09:52.28527193Z 2 PC: 141a5 | Character output (Char = '0d')
2018-12-17T23:09:52.287976394Z 2 PC: 141a5 | Character output (Char = '0a')
2018-12-17T23:09:52.292879461Z 76 PC: 1415a | Terminate with return code (Return code = '0')