Sample viewer

vx.netlux.org/Trojan.DOS.UCF.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:27.558990573Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:22:27.56513727Z 41 PC: 94fae | Parse filename
2018-12-17T22:22:27.570854711Z 41 PC: 9502f | Parse filename
2018-12-17T22:22:27.574142485Z 41 PC: 9504c | Parse filename
2018-12-17T22:22:27.576493779Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:22:27.579254256Z 71 PC: 986f3 | Get current directory
2018-12-17T22:22:27.581988324Z 78 PC: 986fe | Find first file
2018-12-17T22:22:27.592021147Z 71 PC: 986f3 | Get current directory
2018-12-17T22:22:27.596458296Z 78 PC: 986fe | Find first file
2018-12-17T22:22:27.607286769Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T22:22:27.612419717Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:22:27.61473919Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:22:27.616509661Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:27.618104131Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.620548007Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.622293151Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.624054341Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.625815836Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.627937639Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.629608377Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.631249064Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.633463351Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.635076985Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.636708597Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.639363586Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.641064937Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.642756486Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.644973556Z 62 PC: 122ab | Close file
2018-12-17T22:22:27.646817801Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:22:27.648096018Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:22:27.651054679Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:22:27.655893747Z 25 PC: 94e62 | Get default drive
2018-12-17T22:22:27.657410831Z 71 PC: 970dd | Get current directory
2018-12-17T22:22:27.662524596Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:22:27.665990767Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:22:27.668533808Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:22:27.670739754Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:22:27.672946867Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:22:42.605944829Z 0 PC: 0 | Program terminate
2018-12-17T22:22:43.963033606Z 0 PC: 0 | Program terminate
2018-12-17T22:22:44.065714099Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:22:44.072024775Z 41 PC: 94fae | Parse filename
2018-12-17T22:22:44.074055641Z 41 PC: 9502f | Parse filename
2018-12-17T22:22:44.075760576Z 41 PC: 9504c | Parse filename
2018-12-17T22:22:44.07952824Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:22:44.084170927Z 71 PC: 986f3 | Get current directory
2018-12-17T22:22:44.092681885Z 78 PC: 986fe | Find first file
2018-12-17T22:22:44.102644676Z 71 PC: 9856c | Get current directory
2018-12-17T22:22:44.106022235Z 73 PC: 97c09 | Release memory
2018-12-17T22:22:44.107771532Z 75 PC: 11821 | Execute program
2018-12-17T22:22:44.122292882Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:22:44.127921315Z 76 PC: 12a4b | Terminate with return code (Return code = '36')