Sample viewer

vx.netlux.org/Trojan.DOS.Sharecom

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:45.574078362Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:45.575524835Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:45.5912771Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:45.592983637Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:45.595214912Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:45.601066235Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:45.603700462Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:45.606661787Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:45.60936149Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:45.610894949Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:45.612687293Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:45.614968574Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:45.616816375Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:45.61870556Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:45.621338818Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:45.623348367Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:45.624863117Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:45.62633602Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:45.62960539Z 53 PC: 12d72 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:45.631044928Z 37 PC: 12d87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:45.632362232Z 37 PC: 12d8f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:45.63463881Z 37 PC: 12d97 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:45.636418714Z 37 PC: 12d9f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:45.638704606Z 68 PC: 1310f | I/O control for devices (Set for = '')
2018-12-17T23:10:45.644396078Z 61 PC: 1335d | Open file (Filename = 'c:\autoexec.bat')
2018-12-17T23:10:45.652285147Z 66 PC: 134f9 | Move file pointer
2018-12-17T23:10:45.654107678Z 66 PC: 13507 | Move file pointer
2018-12-17T23:10:45.656253325Z 66 PC: 13515 | Move file pointer
2018-12-17T23:10:45.658401266Z 63 PC: 13430 | Read file or device (Read 90 bytes on handle 5)
2018-12-17T23:10:45.661524345Z 62 PC: 133ad | Close file
2018-12-17T23:10:45.664890339Z 60 PC: 1335d | Create or truncate file
2018-12-17T23:10:46.006157644Z 64 PC: 13430 | Write file or device (Write 101 bytes on handle 5)
2018-12-17T23:10:46.015817157Z 62 PC: 133ad | Close file
2018-12-17T23:10:46.025574204Z 48 PC: 13537 | Get DOS version
2018-12-17T23:10:46.027741586Z 61 PC: 1335d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:46.035587669Z 66 PC: 134f9 | Move file pointer
2018-12-17T23:10:46.037586675Z 66 PC: 13507 | Move file pointer
2018-12-17T23:10:46.040683667Z 66 PC: 13515 | Move file pointer
2018-12-17T23:10:46.042778288Z 66 PC: 1348f | Move file pointer
2018-12-17T23:10:46.044861723Z 63 PC: 13430 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:10:46.054622094Z 62 PC: 133ad | Close file
2018-12-17T23:10:46.059649723Z 48 PC: 13537 | Get DOS version
2018-12-17T23:10:46.061729115Z 61 PC: 1335d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:10:46.07071304Z 66 PC: 134f9 | Move file pointer
2018-12-17T23:10:46.073117339Z 66 PC: 13507 | Move file pointer
2018-12-17T23:10:46.07510299Z 66 PC: 13515 | Move file pointer
2018-12-17T23:10:46.077977982Z 66 PC: 1348f | Move file pointer
2018-12-17T23:10:46.096483652Z 63 PC: 13430 | Read file or device (Read 91 bytes on handle 5)
2018-12-17T23:10:46.105101041Z 62 PC: 133ad | Close file
2018-12-17T23:10:46.108229231Z 60 PC: 1335d | Create or truncate file
2018-12-17T23:10:46.121575179Z 64 PC: 13430 | Write file or device (Write 91 bytes on handle 5)
2018-12-17T23:10:46.126027088Z 62 PC: 133ad | Close file
2018-12-17T23:10:46.134783336Z 64 PC: 13212 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:10:46.137606354Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:46.139044646Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:10:46.140427952Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:10:46.143186475Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:46.144853343Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:46.146523428Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:46.149016611Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:10:46.151083472Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:10:46.152778402Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:10:46.155373442Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:10:46.157150979Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:10:46.159675297Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:10:46.161383057Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:10:46.163393939Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:10:46.164721332Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:10:46.166038883Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:10:46.168399398Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:10:46.169708398Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:10:46.171109552Z 37 PC: 12e86 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:10:46.173409994Z 76 PC: 12ec5 | Terminate with return code (Return code = '0')