Sample viewer

vx.netlux.org/Trojan.DOS.AnDum.g

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:13:35.023346678Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:13:35.025155903Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:13:35.027462821Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:13:35.02963868Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:13:35.039733448Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:13:35.041264631Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:35.042736412Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:13:35.045184789Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:13:35.04751315Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:13:35.049698907Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:13:35.051722567Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:13:35.054246004Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:13:35.055734268Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:13:35.057204816Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:13:35.059535908Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:13:35.06078228Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:13:35.061739285Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:13:35.063700324Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:13:35.0649094Z 53 PC: 12d6a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:13:35.066041934Z 37 PC: 12d7f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:13:35.068227844Z 37 PC: 12d87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:13:35.06924258Z 37 PC: 12d8f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:35.070100512Z 37 PC: 12d97 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:13:35.072166587Z 68 PC: 13628 | I/O control for devices (Set for = 'uA &>zr<:t&< u jr <:tuw')
2018-12-17T22:13:35.073843188Z 65 PC: 13579 | Delete file (Filename = 'c:\windows\system.dat')
2018-12-17T22:13:35.084564132Z 64 PC: 13188 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:13:35.089239333Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:13:35.094739853Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:13:35.096191136Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:13:35.09763909Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:13:35.099593361Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:13:35.101068296Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:35.102535838Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:13:35.10496308Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:13:35.106454134Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:13:35.107886418Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:13:35.110274608Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:13:35.11141027Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:13:35.112578019Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:13:35.114321352Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:13:35.116498828Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:13:35.117797553Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:13:35.120436872Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:13:35.121927907Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:13:35.122978248Z 37 PC: 12ec1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:13:35.125050533Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.126996707Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.128871851Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.131968369Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.134384874Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.136589258Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.139226898Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.141913124Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.143882239Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.146319509Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.148662815Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.150833314Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.154286004Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.156469383Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.15868557Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.162321006Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.164376612Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.166527463Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.169442038Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.171577746Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.173832811Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.176922774Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.179325188Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.181657417Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.184397689Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.186881186Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.18913093Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.191576953Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.194089691Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.196301148Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.198731962Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.201033964Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.203862278Z 6 PC: 12f48 | Direct console I/O
2018-12-17T22:13:35.208495227Z 76 PC: 12f00 | Terminate with return code (Return code = '2')