Sample viewer

vx.netlux.org/Trojan.DOS.Dynam

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:36.84067789Z 48 PC: 18a6c | Get DOS version
2018-12-17T22:14:36.855106065Z 74 PC: 18abc | Reallocate memory
2018-12-17T22:14:36.857273563Z 48 PC: 18b20 | Get DOS version
2018-12-17T22:14:36.858698494Z 53 PC: 18b28 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:36.860452466Z 37 PC: 18b3a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:36.862901224Z 53 PC: 1b1c2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:36.864032639Z 37 PC: 1b1d2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:36.866538103Z 53 PC: 1b1d7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:36.871196027Z 37 PC: 1b1e7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:36.872533843Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:36.876763067Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:36.878325451Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:36.879675392Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:36.881746032Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:36.882961484Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:36.884077369Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:36.885896944Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:36.887182337Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:36.888380562Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:36.893516188Z 53 PC: 18f16 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:36.895187178Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:36.8974016Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:36.899651014Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:36.900831559Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:36.901946017Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:36.906444562Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:36.908256865Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:36.910659988Z 37 PC: 18f45 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:36.912853592Z 37 PC: 18f4c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:36.914284667Z 37 PC: 18f51 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:36.915553539Z 68 PC: 18bcb | I/O control for devices (Set for = '��Dt�d����^�')
2018-12-17T22:14:36.917812146Z 68 PC: 18bcb | I/O control for devices (Set for = '~�')
2018-12-17T22:14:36.927063693Z 68 PC: 18bcb | I/O control for devices (Set for = '?} �l�|��\�P')
2018-12-17T22:14:36.928401598Z 68 PC: 18bcb | I/O control for devices (Set for = ' � � � �t�?')
2018-12-17T22:14:36.93253717Z 68 PC: 18bcb | I/O control for devices (Set for = ' � � � �t�?')
2018-12-17T22:14:36.937330679Z 53 PC: 16462 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:36.938829742Z 53 PC: 1646f | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:14:36.940538464Z 53 PC: 1647c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:36.94332348Z 37 PC: 16491 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:36.944409707Z 37 PC: 16499 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:14:36.946317497Z 37 PC: 164a1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:36.947727378Z 53 PC: 16f20 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:14:36.948922472Z 53 PC: 16f2d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:14:36.951709775Z 53 PC: 16f3c | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:14:36.95306274Z 37 PC: 16f49 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:14:36.954342506Z 53 PC: 16f50 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:14:36.955506836Z 37 PC: 16f5d | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:14:36.963497278Z 53 PC: 16f69 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:14:36.968094193Z 48 PC: 1702b | Get DOS version
2018-12-17T22:14:36.969741399Z 74 PC: 1512d | Reallocate memory
2018-12-17T22:14:36.972516808Z 74 PC: 1512d | Reallocate memory
2018-12-17T22:14:36.974141618Z 68 PC: 163d8 | I/O control for devices (Set for = '�������������������������������������������ͻ�K')
2018-12-17T22:14:36.975809533Z 68 PC: 163d8 | I/O control for devices (Set for = '')
2018-12-17T22:14:36.980038455Z 51 PC: 163f6 | Get or set Ctrl-Break
2018-12-17T22:14:36.981165943Z 51 PC: 16402 | Get or set Ctrl-Break
2018-12-17T22:14:36.983367903Z 37 PC: 142e7 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:14:36.986081992Z 71 PC: 137a0 | Get current directory
2018-12-17T22:14:36.998481623Z 26 PC: 13423 | Set disk transfer address
2018-12-17T22:14:36.99995361Z 78 PC: 1342a | Find first file
2018-12-17T22:14:37.009513037Z 74 PC: 1512d | Reallocate memory
2018-12-17T22:14:37.011345319Z 51 PC: 1640d | Get or set Ctrl-Break
2018-12-17T22:14:37.012535404Z 37 PC: 1668f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:37.014604046Z 37 PC: 16699 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:14:37.015988336Z 37 PC: 166a3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:37.017435366Z 53 PC: 14b5a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:14:37.019918662Z 53 PC: 14b67 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:14:37.021433023Z 53 PC: 14b74 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:14:37.022940192Z 37 PC: 14b8f | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:14:37.031694839Z 53 PC: 14b97 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:14:37.032878864Z 37 PC: 14ba4 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:14:37.03396823Z 53 PC: 14bab | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:14:37.035974211Z 37 PC: 14bb8 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:14:37.040020421Z 37 PC: 14bc2 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:14:37.041451159Z 37 PC: 14bcd | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:14:37.043856535Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:14:37.045176695Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:14:37.046534182Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:14:37.050997815Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:14:37.05217589Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:14:37.054881626Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:14:37.056592316Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:14:37.058444489Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:14:37.059462459Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:14:37.063915863Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:14:37.064962111Z 37 PC: 18f61 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:14:37.06601565Z 37 PC: 1b1f6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:37.067553403Z 37 PC: 18c7c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:37.069572131Z 41 PC: 1895d | Parse filename
2018-12-17T22:14:37.07103757Z 41 PC: 1895f | Parse filename
2018-12-17T22:14:37.072849917Z 41 PC: 18964 | Parse filename
2018-12-17T22:14:37.074337277Z 75 PC: 1897a | Execute program
2018-12-17T22:14:37.095265827Z 80 PC: 1e8d9 | Set current PSP
2018-12-17T22:14:37.096585901Z 48 PC: 1e8de | Get DOS version
2018-12-17T22:14:37.098363808Z 99 PC: 250c0 | Get DBCS lead byte table pointer
2018-12-17T22:14:37.100918278Z 101 PC: 1e964 | Get extended country info
2018-12-17T22:14:37.102573329Z 99 PC: 1e96a | Get DBCS lead byte table pointer
2018-12-17T22:14:37.104051325Z 74 PC: 1e9cc | Reallocate memory
2018-12-17T22:14:37.105337076Z 25 PC: 1ea03 | Get default drive
2018-12-17T22:14:37.106861617Z 37 PC: 1e4c3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:14:37.108028945Z 37 PC: 1e4ca | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:37.109138019Z 37 PC: 1e4d1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:37.11640463Z 74 PC: 1d66c | Reallocate memory
2018-12-17T22:14:37.117844802Z 72 PC: 1d6ad | Allocate memory
2018-12-17T22:14:37.12118961Z 72 PC: 1d6e5 | Allocate memory
2018-12-17T22:14:37.123697759Z 72 PC: 1d6ed | Allocate memory