Sample viewer

vx.netlux.org/Trojan.DOS.AnDum.h

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:33.610175483Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:33.612716988Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:33.613887246Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:33.614931071Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:33.616323984Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:33.617694638Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:33.619644404Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:33.620691908Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:33.622318597Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:33.62339249Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:33.625250454Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:33.627185244Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:33.628236628Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:33.629422442Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:33.631015723Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:33.632056244Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:33.633084317Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:33.635102937Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:33.63616259Z 53 PC: 12d9a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:33.637152266Z 37 PC: 12daf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:33.639964534Z 37 PC: 12db7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:33.641624283Z 37 PC: 12dbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:33.642800224Z 37 PC: 12dc7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:33.646411327Z 68 PC: 13658 | I/O control for devices (Set for = '��')
2018-12-17T23:10:33.647772772Z 65 PC: 135a9 | Delete file (Filename = 'c:\windows\system.dat')
2018-12-17T23:10:33.65440214Z 64 PC: 131b8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:10:33.65578144Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:33.657428244Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:33.658566171Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:33.659957272Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:33.667764688Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:33.668821654Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:33.669872594Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:33.671972069Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:33.673381815Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:33.675623214Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:33.6775559Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:33.678978279Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:33.680383591Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:33.682357179Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:33.683548603Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:33.684669985Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:33.686694087Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:33.700564935Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:33.702833573Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:33.704806465Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.707249848Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.709660327Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.712980337Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.715083803Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.717097612Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.720109801Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.722258535Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.724235209Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.72698469Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.729162586Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.73116533Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.733873033Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.735956242Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.738052161Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.740761747Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.74304955Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.745846171Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.748744759Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.750903571Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.753070253Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.756160342Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.758787099Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.761099202Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.763380123Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.76691316Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.769255755Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.772487897Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.775358127Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.77766729Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.779679188Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.782177117Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.78428417Z 6 PC: 12f78 | Direct console I/O
2018-12-17T23:10:33.788100701Z 76 PC: 12f30 | Terminate with return code (Return code = '2')