Sample viewer

vx.netlux.org/Trojan.DOS.InstallVivid

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:42.344680448Z 53 PC: 13802 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:42.347228329Z 53 PC: 13802 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:42.349340911Z 53 PC: 13802 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:42.350733664Z 53 PC: 13802 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:42.351935891Z 53 PC: 13802 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:42.358687582Z 53 PC: 13802 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:42.361243361Z 53 PC: 13802 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:42.363230842Z 53 PC: 13802 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:42.366084887Z 53 PC: 13802 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:42.36750642Z 53 PC: 13802 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:42.368942075Z 53 PC: 13802 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:42.371750548Z 53 PC: 13802 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:42.373406738Z 53 PC: 13802 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:42.374776512Z 53 PC: 13802 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:42.376253905Z 53 PC: 13802 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:42.378221474Z 53 PC: 13802 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:42.380257509Z 53 PC: 13802 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:42.38228175Z 53 PC: 13802 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:42.384786804Z 53 PC: 13802 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:42.386299745Z 37 PC: 13817 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:42.387743785Z 37 PC: 1381f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:42.391487279Z 37 PC: 13827 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:42.393139365Z 37 PC: 1382f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:42.395388053Z 68 PC: 13b9f | I/O control for devices (Set for = '')
2018-12-17T22:20:42.494002657Z 37 PC: 130b5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:42.495796788Z 53 PC: 1364f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:20:42.49738769Z 37 PC: 1366b | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:20:42.510285831Z 44 PC: 141e6 | Get time 0x141e6: mov word ptr [0x3e], cx
0x141ea: mov word ptr [0x40], dx
0x141ee: retf
0x141ef: mov bx, sp
0x141f1: push ds
0x141f2: les di, ptr ss:[bx + 8]
0x141f6: lds si, ptr ss:[bx + 4]
0x141fa: cld
0x141fb: xor ax, ax
0x141fd: stosw word ptr es:[di], ax
0x141fe: mov ax, 0xd7b0
0x14201: stosw word ptr es:[di], ax
0x14202: xor ax, ax
0x14204: mov cx, 0x16
0x14207: rep stosd dword ptr es:[di], eax
0x14209: lodsb al, byte ptr [si]
0x1420a: cmp al, 0x4f
0x1420c: jbe 0x14210
0x1420e: mov al, 0x4f
0x14210: mov cl, al
2018-12-17T22:20:42.519808075Z 48 PC: 13644 | Get DOS version
2018-12-17T22:20:42.521191687Z 48 PC: 144a5 | Get DOS version
2018-12-17T22:20:42.523103292Z 48 PC: 144a5 | Get DOS version
2018-12-17T22:20:42.5253049Z 48 PC: 144a5 | Get DOS version
2018-12-17T22:20:42.527406883Z 61 PC: 14265 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:42.535144781Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.538016533Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.540068258Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.542407525Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.567367197Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.569364785Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.57134857Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.574048053Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.581880944Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.583425303Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.585930452Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.587607895Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.596605374Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.59827926Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.600341899Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.603015697Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.610973865Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.614161963Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.616332265Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.618615705Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.627779916Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.62972353Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.632264816Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.635223443Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.644340022Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.646649303Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.649903947Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.653306507Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.661981377Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.665783894Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.668544247Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.671504452Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.679815593Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.698476717Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.700051633Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.701736913Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.708430704Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.709639115Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.710758111Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.712529771Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.717446637Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.718723886Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.720534034Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.721764574Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.726589572Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.728730801Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.730193292Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.731651308Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.739843283Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.741026617Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.742236448Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.744878021Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.749869852Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.751394509Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.753134899Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.754877832Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.762667769Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.764341516Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.766142908Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.767813646Z 64 PC: 14338 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:20:42.776164437Z 66 PC: 14401 | Move file pointer
2018-12-17T22:20:42.779040284Z 66 PC: 1440f | Move file pointer
2018-12-17T22:20:42.780804295Z 66 PC: 1441d | Move file pointer
2018-12-17T22:20:42.782877187Z 62 PC: 142b5 | Close file
2018-12-17T22:20:42.792608442Z 65 PC: 1443a | Delete file (Filename = 'A:\TEST.EXE')
2018-12-17T22:20:43.144288024Z 61 PC: 13b86 | Open file (Filename = 'A:\INSTALL.DAT')
2018-12-17T22:20:43.152402117Z 37 PC: 13916 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:43.155477851Z 37 PC: 13916 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:43.157452609Z 37 PC: 13916 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:43.159348275Z 37 PC: 13916 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:43.161300216Z 37 PC: 13916 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:43.163706458Z 37 PC: 13916 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:43.165322134Z 37 PC: 13916 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:43.166947134Z 37 PC: 13916 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:43.169060414Z 37 PC: 13916 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:43.170691254Z 37 PC: 13916 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:43.172317628Z 37 PC: 13916 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:43.174566748Z 37 PC: 13916 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:43.175975929Z 37 PC: 13916 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:43.177327656Z 37 PC: 13916 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:43.179800577Z 37 PC: 13916 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:43.181492682Z 37 PC: 13916 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:43.182762166Z 37 PC: 13916 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:43.184148164Z 37 PC: 13916 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:43.185596788Z 37 PC: 13916 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:43.187391336Z 76 PC: 13955 | Terminate with return code (Return code = '0')