Sample viewer

vx.netlux.org/Trojan.DOS.Detroit

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:12:23.30362806Z 56 PC: 16cb9 | Get or set country info
2018-12-17T22:12:23.30584051Z 52 PC: 15f12 | Get InDOS flag pointer
2018-12-17T22:12:23.306944881Z 74 PC: 13d77 | Reallocate memory
2018-12-17T22:12:23.309719251Z 53 PC: 1630f | Get interrupt vector (Interrupt = '103' AKA 'Set handle count')
2018-12-17T22:12:23.311155034Z 37 PC: 16326 | Set interrupt vector (Interrupt = '103' AKA 'Set handle count')
2018-12-17T22:12:23.31219084Z 37 PC: 16335 | Set interrupt vector (Interrupt = '103' AKA 'Set handle count')
2018-12-17T22:12:23.313685491Z 61 PC: 1552a | Open file (Filename = 'S�')
2018-12-17T22:12:23.324070971Z 66 PC: 15543 | Move file pointer
2018-12-17T22:12:23.325679054Z 63 PC: 15578 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.327671448Z 66 PC: 15543 | Move file pointer
2018-12-17T22:12:23.330077525Z 63 PC: 15578 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.337494014Z 66 PC: 15543 | Move file pointer
2018-12-17T22:12:23.339694271Z 63 PC: 15578 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.346874959Z 66 PC: 15543 | Move file pointer
2018-12-17T22:12:23.348046817Z 63 PC: 15578 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.356216575Z 66 PC: 15543 | Move file pointer
2018-12-17T22:12:23.357708129Z 63 PC: 15578 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.360232272Z 72 PC: 15ff9 | Allocate memory
2018-12-17T22:12:23.36313993Z 64 PC: 1482a | Write file or device (Write 2147483655 bytes on handle 2)
2018-12-17T22:12:23.366328039Z 64 PC: 1482a | Write file or device (Write 2147483685 bytes on handle 2)
2018-12-17T22:12:23.369086264Z 64 PC: 1482a | Write file or device (Write 2147483652 bytes on handle 2)
2018-12-17T22:12:23.372388047Z 64 PC: 1482a | Write file or device (Write 2147483650 bytes on handle 2)
2018-12-17T22:12:23.376598947Z 64 PC: 1482a | Write file or device (Write 2147483697 bytes on handle 2)
2018-12-17T22:12:23.380904264Z 64 PC: 1482a | Write file or device (Write 2147483650 bytes on handle 2)
2018-12-17T22:12:23.385940271Z 53 PC: 19531 | Get interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:12:23.387164438Z 37 PC: 19545 | Set interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:12:23.388709856Z 53 PC: 19569 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:12:23.390292633Z 37 PC: 1957d | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:12:23.393864659Z 72 PC: 19664 | Allocate memory
2018-12-17T22:12:23.401244922Z 51 PC: 14ca7 | Get or set Ctrl-Break
2018-12-17T22:12:23.403572274Z 51 PC: 14ca7 | Get or set Ctrl-Break
2018-12-17T22:12:23.40569497Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.409368256Z 63 PC: 14ca7 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.421408882Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.426417929Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.431021333Z 63 PC: 14ca7 | Read file or device (Read 2147483712 bytes on handle 5)
2018-12-17T22:12:23.437251045Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.441977154Z 63 PC: 14ca7 | Read file or device (Read 2147488624 bytes on handle 5)
2018-12-17T22:12:23.449197726Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.454185855Z 63 PC: 14ca7 | Read file or device (Read 2147483792 bytes on handle 5)
2018-12-17T22:12:23.459394712Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.464514808Z 63 PC: 14ca7 | Read file or device (Read 2147487488 bytes on handle 5)
2018-12-17T22:12:23.474586545Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.479294155Z 63 PC: 14ca7 | Read file or device (Read 2147485328 bytes on handle 5)
2018-12-17T22:12:23.489839686Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.49446507Z 63 PC: 14ca7 | Read file or device (Read 2147483968 bytes on handle 5)
2018-12-17T22:12:23.503233091Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.508455909Z 63 PC: 14ca7 | Read file or device (Read 2147483968 bytes on handle 5)
2018-12-17T22:12:23.51449574Z 73 PC: 14ca7 | Release memory
2018-12-17T22:12:23.518456454Z 73 PC: 14ca7 | Release memory
2018-12-17T22:12:23.522777687Z 73 PC: 14ca7 | Release memory
2018-12-17T22:12:23.526398177Z 51 PC: 14ca7 | Get or set Ctrl-Break
2018-12-17T22:12:23.528317067Z 74 PC: 13d77 | Reallocate memory
2018-12-17T22:12:23.531895389Z 48 PC: 14ca7 | Get DOS version
2018-12-17T22:12:23.534044709Z 48 PC: 14ca7 | Get DOS version
2018-12-17T22:12:23.537667676Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.54126584Z 68 PC: 14ca7 | I/O control for devices (Set for = '')
2018-12-17T22:12:23.543543795Z 68 PC: 14ca7 | I/O control for devices (Set for = '9')
2018-12-17T22:12:23.546789428Z 68 PC: 14ca7 | I/O control for devices (Set for = 'u �~�6�>�����6mU��][���m�v�s6�6�6��3ɈL�DI��6�6��DC')
2018-12-17T22:12:23.549217735Z 68 PC: 14ca7 | I/O control for devices (Set for = 'U��][���m�v�s6�6�6��3ɈL�DI��6�6��DC')
2018-12-17T22:12:23.551577147Z 68 PC: 14ca7 | I/O control for devices (Set for = 'U��][���m�v�s6�6�6��3ɈL�DI��6�6��DC')
2018-12-17T22:12:23.557659236Z 51 PC: 14ca7 | Get or set Ctrl-Break
2018-12-17T22:12:23.559675036Z 51 PC: 14ca7 | Get or set Ctrl-Break
2018-12-17T22:12:23.561890852Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.565844918Z 63 PC: 14ca7 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.57124648Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.576555278Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.58127268Z 63 PC: 14ca7 | Read file or device (Read 2147483680 bytes on handle 5)
2018-12-17T22:12:23.586591155Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.592426067Z 63 PC: 14ca7 | Read file or device (Read 2147534496 bytes on handle 5)
2018-12-17T22:12:23.605039133Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.610492817Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.615645627Z 63 PC: 14ca7 | Read file or device (Read 2147488608 bytes on handle 5)
2018-12-17T22:12:23.624984746Z 62 PC: 14ca7 | Close file
2018-12-17T22:12:23.627921238Z 73 PC: 14ca7 | Release memory
2018-12-17T22:12:23.63059777Z 51 PC: 14ca7 | Get or set Ctrl-Break
2018-12-17T22:12:23.632661162Z 73 PC: 14ca7 | Release memory
2018-12-17T22:12:23.635262061Z 73 PC: 14ca7 | Release memory
2018-12-17T22:12:23.638290264Z 48 PC: 14ca7 | Get DOS version
2018-12-17T22:12:23.641595976Z 103 PC: 14ca7 | Set handle count
2018-12-17T22:12:23.645534391Z 68 PC: 14ca7 | I/O control for devices (Set for = ' ��6�#�밋��o�rW^��')
2018-12-17T22:12:23.647327364Z 68 PC: 14ca7 | I/O control for devices (Set for = '9')
2018-12-17T22:12:23.649628183Z 68 PC: 14ca7 | I/O control for devices (Set for = 'u �~�6�>�����6mU��][���m�v�s6�6�6��3ɈL�DI��6�6��DC')
2018-12-17T22:12:23.652601251Z 68 PC: 14ca7 | I/O control for devices (Set for = 'U��][���m�v�s6�6�6��3ɈL�DI��6�6��DC')
2018-12-17T22:12:23.655026359Z 68 PC: 14ca7 | I/O control for devices (Set for = 'U��][���m�v�s6�6�6��3ɈL�DI��6�6��DC')
2018-12-17T22:12:23.658815472Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.665638258Z 42 PC: 14ca7 | Get date 0x14ca7: pushf
0x14ca8: pop word ptr cs:[0x1556]
0x14cad: cli
0x14cae: mov ss, word ptr cs:[0]
0x14cb3: mov sp, word ptr cs:[0x1554]
0x14cb8: pushaw
0x14cb9: push es
0x14cba: push ds
0x14cbb: mov ds, word ptr cs:[0]
0x14cc0: call 0x243a8
0x14cc3: mov ax, word ptr cs:[0x1556]
0x14cc7: ljmp 0x70:0x4d52
0x14ccc: pushf
0x14ccd: push cs
0x14cce: push 0x15d5
0x14cd1: call 0x23961
2018-12-17T22:12:23.668144244Z 61 PC: 14ca7 | Open file (Filename = ']:|<>+=;,')
2018-12-17T22:12:23.673601Z 68 PC: 14ca7 | I/O control for devices (Set for = ']:|<>+=;,')
2018-12-17T22:12:23.675307879Z 67 PC: 14ca7 | Get or set file attributes
2018-12-17T22:12:23.679555322Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.681900452Z 63 PC: 14ca7 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.684532691Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.687262496Z 63 PC: 14ca7 | Read file or device (Read 2147483824 bytes on handle 5)
2018-12-17T22:12:23.696990427Z 90 PC: 14ca7 | Create unique file
2018-12-17T22:12:23.71730801Z 66 PC: 14ca7 | Move file pointer
2018-12-17T22:12:23.719949311Z 64 PC: 14ca7 | Write file or device (Write 2147483649 bytes on handle 6)
2018-12-17T22:12:23.733113471Z 68 PC: 14ca7 | I/O control for devices (Set for = '')
2018-12-17T22:12:23.736149892Z 54 PC: 14ca7 | Get free disk space
2018-12-17T22:12:23.748210549Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.753418633Z 74 PC: 14ca7 | Reallocate memory
2018-12-17T22:12:23.756893003Z 72 PC: 14ca7 | Allocate memory
2018-12-17T22:12:23.761558407Z 72 PC: 14ca7 | Allocate memory