Sample viewer

vx.netlux.org/Trojan.DOS.AidsInfo.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:36.99531249Z 48 PC: 2fa56 | Get DOS version
2018-12-17T22:21:36.997979281Z 74 PC: 29826 | Reallocate memory
2018-12-17T22:21:36.999353731Z 72 PC: 22fe2 | Allocate memory
2018-12-17T22:21:37.002687588Z 48 PC: 2304c | Get DOS version
2018-12-17T22:21:37.004242722Z 68 PC: 232c9 | I/O control for devices (Set for = '')
2018-12-17T22:21:37.005657352Z 68 PC: 232c9 | I/O control for devices (Set for = '')
2018-12-17T22:21:37.007817656Z 51 PC: 236ad | Get or set Ctrl-Break
2018-12-17T22:21:37.0088033Z 51 PC: 236b9 | Get or set Ctrl-Break
2018-12-17T22:21:37.009813482Z 53 PC: 236c4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:37.01168473Z 53 PC: 236d1 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:21:37.012926654Z 53 PC: 236de | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:37.014487947Z 37 PC: 236f4 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:37.016477008Z 37 PC: 236fc | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:21:37.029736431Z 37 PC: 23704 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:37.031723763Z 53 PC: 27eb2 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:21:37.033864117Z 53 PC: 27ebf | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:21:37.035851072Z 53 PC: 27ece | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:21:37.038017209Z 37 PC: 27edb | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:21:37.040058843Z 53 PC: 27ee2 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:21:37.042084651Z 37 PC: 27eef | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:21:37.044587327Z 53 PC: 27efb | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:21:37.049377253Z 48 PC: 27fea | Get DOS version
2018-12-17T22:21:37.050831071Z 37 PC: 27859 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:21:37.05335008Z 37 PC: 29ce4 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:21:37.055988682Z 37 PC: 27859 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:21:37.065865643Z 61 PC: 26c1c | Open file (Filename = 'C:\ \ \ \___. _')
2018-12-17T22:21:37.075569984Z 61 PC: 26c1c | Open file (Filename = 'C:\ \ \ \_. _')
2018-12-17T22:21:37.084284256Z 61 PC: 26c1c | Open file (Filename = 'A:INSTALL.EXE')
2018-12-17T22:21:37.093113954Z 61 PC: 26c1c | Open file (Filename = 'A:SHARE.EXE')
2018-12-17T22:21:37.10546571Z 61 PC: 26c1c | Open file (Filename = 'C:\ \ \ \_. _')