Sample viewer

vx.netlux.org/Trojan.DOS.EatFlu.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:16:15.267426431Z 48 PC: 12a4b | Get DOS version
2018-12-17T22:16:15.269542243Z 53 PC: 12b83 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:16:15.271076384Z 53 PC: 12b90 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:16:15.272449073Z 53 PC: 12b9d | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:16:15.274291851Z 53 PC: 12baa | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:16:15.275386539Z 37 PC: 12bbe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:16:15.276640645Z 74 PC: 12af3 | Reallocate memory
2018-12-17T22:16:15.279179012Z 68 PC: 138f4 | I/O control for devices (Set for = '')
2018-12-17T22:16:15.282165243Z 68 PC: 138f4 | I/O control for devices (Set for = ' ')
2018-12-17T22:16:15.284474898Z 59 PC: 137cf | Change current directory
2018-12-17T22:16:15.287304737Z 255 PC: 12c98 | UNKNOWN!
2018-12-17T22:16:15.288655079Z 42 PC: 130bd | Get date 0x130bd: mov word ptr [si], cx
0x130bf: mov word ptr [si + 2], dx
0x130c2: pop si
0x130c3: pop bp
0x130c4: ret
0x130c5: push bp
0x130c6: mov bp, sp
0x130c8: push si
0x130c9: mov si, word ptr [bp + 4]
0x130cc: mov ah, 0x2c
0x130ce: int 0x21
0x130d0: mov word ptr [si], cx
0x130d2: mov word ptr [si + 2], dx
0x130d5: pop si
0x130d6: pop bp
0x130d7: ret
0x130d8: push bp
0x130d9: mov bp, sp
0x130db: mov ax, word ptr [bp + 4]
0x130de: mov word ptr [0x1b12], 0
2018-12-17T22:16:15.2902167Z 44 PC: 130d0 | Get time 0x130d0: mov word ptr [si], cx
0x130d2: mov word ptr [si + 2], dx
0x130d5: pop si
0x130d6: pop bp
0x130d7: ret
0x130d8: push bp
0x130d9: mov bp, sp
0x130db: mov ax, word ptr [bp + 4]
0x130de: mov word ptr [0x1b12], 0
0x130e4: mov word ptr [0x1b10], ax
0x130e7: pop bp
0x130e8: ret
0x130e9: mov cx, word ptr [0x1b12]
0x130ed: mov bx, word ptr [0x1b10]
0x130f1: mov dx, 0x15a
0x130f4: mov ax, 0x4e35
0x130f7: call 0x13faf
0x130fa: add ax, 1
0x130fd: adc dx, 0
0x13100: mov word ptr [0x1b12], dx
2018-12-17T22:16:15.29235873Z 47 PC: 137f6 | Get disk transfer address
2018-12-17T22:16:15.293971959Z 26 PC: 137ff | Set disk transfer address
2018-12-17T22:16:15.295396369Z 78 PC: 13809 | Find first file
2018-12-17T22:16:15.301382267Z 26 PC: 13812 | Set disk transfer address
2018-12-17T22:16:15.304136468Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.319752777Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.321293585Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.323718118Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.326217419Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.327395842Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.346728687Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.348885941Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.350404477Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.361694021Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.365041497Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.378935494Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.380439847Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.382869709Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.385822372Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.388642104Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.396023808Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.397468318Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.399574509Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.402832855Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.40491002Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.416031819Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.417844874Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.419068689Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.421576165Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.424068705Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.430230521Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.431279204Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.432697696Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.43527708Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.436668384Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.448254028Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.449645084Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.450894053Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.453886477Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.455785339Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.467182947Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.469431241Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.470561586Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.473001589Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.474387119Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.487234433Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.488308566Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.489589869Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.492593746Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.494434652Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.506269049Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.508302778Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.509653516Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.512349382Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.514995551Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.524774645Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.526192325Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.528179383Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.535455283Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.536858813Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.548273763Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.549339099Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.551091314Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.554106932Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.555240095Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.566243391Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.568620356Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.569980184Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.572805269Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.575631298Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.589763859Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.591227682Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.593399186Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.596166924Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.597841084Z 86 PC: 12df7 | Rename file
2018-12-17T22:16:15.612440766Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.614085093Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.615365796Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.62612157Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.627421172Z 47 PC: 137f6 | Get disk transfer address
2018-12-17T22:16:15.628927337Z 26 PC: 137ff | Set disk transfer address
2018-12-17T22:16:15.630624008Z 78 PC: 13809 | Find first file
2018-12-17T22:16:15.637039181Z 26 PC: 13812 | Set disk transfer address
2018-12-17T22:16:15.638601614Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.640322406Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.641942182Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.644453688Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.646069071Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.648269635Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.649556323Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.65245442Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.654544192Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.655968994Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.657440726Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.660930766Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.662359109Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.663699866Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.665684611Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.688789123Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.691235223Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.693848496Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.695418906Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.698483302Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.701484932Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.703085399Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.704675625Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.708426522Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.70988698Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.711220999Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.713441752Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.715972656Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.717277819Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.719436742Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.720647311Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.7236429Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.726330102Z 47 PC: 13829 | Get disk transfer address
2018-12-17T22:16:15.727499312Z 26 PC: 13832 | Set disk transfer address
2018-12-17T22:16:15.728703731Z 79 PC: 13836 | Find next file
2018-12-17T22:16:15.733322137Z 26 PC: 1383f | Set disk transfer address
2018-12-17T22:16:15.734889643Z 37 PC: 12bca | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:16:15.735995402Z 37 PC: 12bd5 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:16:15.73781609Z 37 PC: 12be0 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:16:15.739456572Z 37 PC: 12beb | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:16:15.741042502Z 76 PC: 12b74 | Terminate with return code (Return code = '0')