Sample viewer

vx.netlux.org/Trojan.DOS.CDA

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:52:02.009650153Z 53 PC: 13376 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:02.011393337Z 53 PC: 13376 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:02.013379374Z 53 PC: 13376 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:02.01466109Z 53 PC: 13376 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:02.016018043Z 53 PC: 13376 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:02.018174016Z 53 PC: 13376 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:02.019581956Z 53 PC: 13376 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:02.020983094Z 53 PC: 13376 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:02.023394475Z 53 PC: 13376 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:02.024773882Z 53 PC: 13376 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:02.02616256Z 53 PC: 13376 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:02.028631462Z 53 PC: 13376 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:02.030030748Z 53 PC: 13376 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:02.03138192Z 53 PC: 13376 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:02.033846186Z 53 PC: 13376 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:02.035269749Z 53 PC: 13376 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:02.036515282Z 53 PC: 13376 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:02.037786193Z 53 PC: 13376 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:02.048181369Z 37 PC: 1338b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:02.049281438Z 37 PC: 13393 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:02.050382214Z 37 PC: 1339b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:02.053300955Z 37 PC: 133a3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:02.055323973Z 68 PC: 136e8 | I/O control for devices (Set for = '')
2018-12-17T21:52:02.129857452Z 37 PC: 12da7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:02.132724788Z 14 PC: 13a05 | Set default drive (Drive = 'C')
2018-12-17T21:52:02.134226275Z 25 PC: 13a09 | Get default drive
2018-12-17T21:52:02.135591337Z 59 PC: 13a73 | Change current directory
2018-12-17T21:52:02.141445202Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T21:52:02.146910662Z 60 PC: 136cf | Create or truncate file
2018-12-17T21:52:02.517385374Z 68 PC: 136e8 | I/O control for devices (Set for = 'IBMBIO.COM')
2018-12-17T21:52:02.520478358Z 64 PC: 137c6 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T21:52:02.523567384Z 62 PC: 13805 | Close file
2018-12-17T21:52:02.530471276Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T21:52:02.540714302Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T21:52:02.546587559Z 60 PC: 136cf | Create or truncate file
2018-12-17T21:52:02.554862171Z 68 PC: 136e8 | I/O control for devices (Set for = 'IBMDOS.COM')
2018-12-17T21:52:02.556798715Z 64 PC: 137c6 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T21:52:02.558377565Z 62 PC: 13805 | Close file
2018-12-17T21:52:02.563239955Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T21:52:02.57507739Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T21:52:02.584230888Z 60 PC: 136cf | Create or truncate file
2018-12-17T21:52:02.59650374Z 68 PC: 136e8 | I/O control for devices (Set for = 'C:\COMMAND.COM')
2018-12-17T21:52:02.598701265Z 64 PC: 137c6 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T21:52:02.601504758Z 62 PC: 13805 | Close file
2018-12-17T21:52:02.608760011Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T21:52:02.61938326Z 60 PC: 136cf | Create or truncate file
2018-12-17T21:52:02.632185549Z 68 PC: 136e8 | I/O control for devices (Set for = 'AUTOEXEC.BAT')
2018-12-17T21:52:02.634105048Z 64 PC: 137c6 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T21:52:02.636801226Z 62 PC: 13805 | Close file
2018-12-17T21:52:02.64554075Z 37 PC: 13485 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:52:02.647014727Z 37 PC: 13485 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:52:02.648459692Z 37 PC: 13485 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:52:02.650882949Z 37 PC: 13485 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:52:02.65237129Z 37 PC: 13485 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:02.653726376Z 37 PC: 13485 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:52:02.655868179Z 37 PC: 13485 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:52:02.65695674Z 37 PC: 13485 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:52:02.658040229Z 37 PC: 13485 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:52:02.659803503Z 37 PC: 13485 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:52:02.661101123Z 37 PC: 13485 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:52:02.662546384Z 37 PC: 13485 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:52:02.664313635Z 37 PC: 13485 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:52:02.665582122Z 37 PC: 13485 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:52:02.666996491Z 37 PC: 13485 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:52:02.668974172Z 37 PC: 13485 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:52:02.670313289Z 37 PC: 13485 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:52:02.671716309Z 37 PC: 13485 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:52:02.673692105Z 76 PC: 134c4 | Terminate with return code (Return code = '0')