Sample viewer

vx.netlux.org/Trojan.DOS.Rob.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:16.271395764Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.272762872Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.276002976Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.290358612Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.292316983Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.296091098Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.309689706Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.311535245Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.314083963Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.333696481Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.347365016Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.349797944Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.370599636Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.386840177Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.38875869Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.403596986Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.405177479Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.406909372Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.422056678Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.423409305Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.439581134Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.453313272Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.454783194Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.456555178Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.472189527Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.475437246Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.492621881Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.508395368Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.509980883Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.511735339Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.526421314Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.528983448Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.530816749Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.546083477Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.548291287Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.55013276Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.563885707Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.565962502Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.567439313Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.58076298Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.583614651Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.58596107Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.599706154Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.602237738Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.604553974Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.620403778Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.622518147Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.624556013Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.645929774Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.647539791Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.649826467Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.664000025Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.665650421Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.670458253Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.686130178Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.687798312Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.690449797Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.704667356Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.706174633Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.7084981Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.721547153Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.723140703Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.725580575Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.739783435Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.741716087Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.743829736Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.758412631Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.760355768Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.76245673Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.778376691Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.780572055Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.78511592Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.799423626Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.801601121Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.803616248Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.822767573Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.824591635Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.826443185Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.839688572Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.841832016Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.845095757Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.888216939Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.890645394Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.892283425Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.913399311Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.915743794Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.917208752Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.930728386Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.932717607Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.93418272Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.947220472Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.949192697Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.950830215Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.980724329Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.982349278Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:16.984302514Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:16.998147887Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:16.999760411Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.006096376Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.018863402Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.020423296Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.023318348Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.036432047Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.037918868Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.040459676Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.053333364Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.05445774Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.056258862Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.070447751Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.071709666Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.073673766Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.086577432Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.087877171Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.089586359Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.104689486Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.106051074Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.10773504Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.122072392Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.124345481Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.125939257Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.146347822Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.147708625Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.149177Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.163247991Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.164815553Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.166679667Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.186426757Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.18811084Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.189841716Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.204599051Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.206419174Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.209511109Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.224168464Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.226082272Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.2281236Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.241786383Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.243219068Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.244736649Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.259209653Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.261535373Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.263387171Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.278067825Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.280221502Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.282202322Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.307664223Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.309913299Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.311849474Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.326869888Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.328481216Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.335245761Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.362051563Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.363799823Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.36532787Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.37890107Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.380806072Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.382798521Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.397421416Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.400382969Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.402390706Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.415844807Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.419286562Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.421301756Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.434848375Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.436928719Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.438369974Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.452148678Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.454002245Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.455996059Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.469396601Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.472486701Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.474799071Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.491044938Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.494530306Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.496004256Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.508800718Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.510829038Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.52178289Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.535020627Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.538074056Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.539746495Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.55292693Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.555411736Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.557122255Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.570303229Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.572826213Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.574733118Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.589128015Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.601823001Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.603533089Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.616922956Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.619966244Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.622265537Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.635422Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.637054199Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.639866212Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.651056009Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.65270178Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.655513971Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.668628545Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.670190154Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.672419215Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.685969122Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.687468483Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.690032348Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.703750183Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.705361457Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.70816239Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.722524704Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.724099642Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.726797054Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.740906604Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.742502659Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.745258217Z 9 PC: 12a76 | Display string (Could not find end pointer)
2018-12-17T23:12:17.758274984Z 48 PC: 12a44 | Get DOS version
2018-12-17T23:12:17.759938333Z 53 PC: 12a4f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:12:17.762332938Z 9 PC: 12a76 | Display string (Could not find end pointer)