Sample viewer

vx.netlux.org/Trojan.DOS.MkDirs.i

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:31.488282961Z 53 PC: 137aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:31.490258082Z 53 PC: 137aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:31.49146981Z 53 PC: 137aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:31.492663444Z 53 PC: 137aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:31.494779089Z 53 PC: 137aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:31.496284141Z 53 PC: 137aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:31.497785181Z 53 PC: 137aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:31.49952298Z 53 PC: 137aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:31.501004994Z 53 PC: 137aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:31.502262201Z 53 PC: 137aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:31.503496916Z 53 PC: 137aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:31.505947299Z 53 PC: 137aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:31.507983757Z 53 PC: 137aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:31.509492502Z 53 PC: 137aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:31.519368012Z 53 PC: 137aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:31.520730058Z 53 PC: 137aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:31.522630254Z 53 PC: 137aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:31.524534386Z 53 PC: 137aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:31.525991608Z 53 PC: 137aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:31.527578947Z 37 PC: 137bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:31.529687366Z 37 PC: 137c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:31.530908179Z 37 PC: 137cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:31.532086892Z 37 PC: 137d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:31.534393581Z 68 PC: 141c7 | I/O control for devices (Set for = '�����8')
2018-12-17T22:21:31.641176491Z 37 PC: 13191 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:31.642828889Z 44 PC: 1465f | Get time 0x1465f: mov word ptr [0x3e], cx
0x14663: mov word ptr [0x40], dx
0x14667: retf
0x14668: mov cx, di
0x1466a: mov si, 0xa
0x1466d: mov bx, dx
0x1466f: or bx, bx
0x14671: jns 0x14684
0x14673: neg bx
0x14675: neg ax
0x14677: sbb bx, 0
0x1467a: call 0x14684
0x1467d: dec di
0x1467e: mov byte ptr es:[di], 0x2d
0x14682: inc cx
0x14683: ret
0x14684: xor dx, dx
0x14686: xchg ax, bx
0x14687: div si
0x14689: xchg ax, bx
2018-12-17T22:21:31.64809052Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.691138806Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.697678674Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.701962028Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.704826791Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.706475411Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.708213071Z 54 PC: 1371a | Get free disk space
2018-12-17T22:21:31.790796372Z 57 PC: 13f5b | Create subdirectory
2018-12-17T22:21:31.795738962Z 37 PC: 13901 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:31.796928509Z 37 PC: 13901 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:31.798459517Z 37 PC: 13901 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:31.799406205Z 37 PC: 13901 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:31.800274912Z 37 PC: 13901 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:31.801660399Z 37 PC: 13901 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:31.802599332Z 37 PC: 13901 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:31.803499761Z 37 PC: 13901 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:31.810252929Z 37 PC: 13901 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:31.811842437Z 37 PC: 13901 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:31.813028414Z 37 PC: 13901 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:31.814829491Z 37 PC: 13901 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:31.815971263Z 37 PC: 13901 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:31.816997526Z 37 PC: 13901 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:31.818704609Z 37 PC: 13901 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:31.820779442Z 37 PC: 13901 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:31.822169274Z 37 PC: 13901 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:31.823859247Z 37 PC: 13901 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:31.825279667Z 37 PC: 13901 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:31.826740948Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.829226519Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.830862991Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.832432276Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.83435598Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.836987006Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.839171461Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.841497292Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.843971887Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.846204773Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.848421644Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.851288041Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.853485724Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.855753609Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.858349906Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.860570131Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.862793938Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.865675085Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.868114821Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.870211464Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.872813616Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.8750484Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.87722742Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.880879809Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.885510144Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.887638062Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.890754115Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.89336129Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.895520071Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.898460287Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.902020182Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.905253172Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.908564609Z 6 PC: 13988 | Direct console I/O
2018-12-17T22:21:31.911254957Z 76 PC: 13940 | Terminate with return code (Return code = '3')