Sample viewer

vx.netlux.org/Trojan.DOS.Half

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:18.99786439Z 53 PC: 12cba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:19.014814232Z 53 PC: 12cba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:19.016681004Z 53 PC: 12cba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:19.01810427Z 53 PC: 12cba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:19.019487278Z 53 PC: 12cba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:19.033952342Z 53 PC: 12cba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:19.03618688Z 53 PC: 12cba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:19.03787538Z 53 PC: 12cba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:19.046640629Z 53 PC: 12cba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:19.047965645Z 53 PC: 12cba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:19.049277692Z 53 PC: 12cba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:19.051580543Z 53 PC: 12cba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:19.053196034Z 53 PC: 12cba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:19.055609886Z 53 PC: 12cba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:19.057212824Z 53 PC: 12cba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:19.059674528Z 53 PC: 12cba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:19.06127891Z 53 PC: 12cba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:19.0629033Z 53 PC: 12cba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:19.06548985Z 53 PC: 12cba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:19.067127634Z 37 PC: 12ccf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:19.068638085Z 37 PC: 12cd7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:19.070610645Z 37 PC: 12cdf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:19.087343985Z 37 PC: 12ce7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:19.089300989Z 68 PC: 134fc | I/O control for devices (Set for = '듎 uÎؿ ')
2018-12-17T22:24:19.092324176Z 14 PC: 13329 | Set default drive (Drive = 'C')
2018-12-17T22:24:19.094002742Z 25 PC: 1332d | Get default drive
2018-12-17T22:24:19.095475699Z 59 PC: 13397 | Change current directory
2018-12-17T22:24:19.100953015Z 14 PC: 13329 | Set default drive (Drive = 'C')
2018-12-17T22:24:19.102789238Z 25 PC: 1332d | Get default drive
2018-12-17T22:24:19.104847955Z 59 PC: 13397 | Change current directory
2018-12-17T22:24:19.122747546Z 26 PC: 12c07 | Set disk transfer address
2018-12-17T22:24:19.142612201Z 78 PC: 12c13 | Find first file
2018-12-17T22:24:19.149907554Z 67 PC: 12bd6 | Get or set file attributes
2018-12-17T22:24:19.489215408Z 57 PC: 13397 | Create subdirectory
2018-12-17T22:24:19.506880119Z 58 PC: 13397 | Remove subdirectory
2018-12-17T22:24:19.51834138Z 61 PC: 1317d | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:24:19.525024651Z 66 PC: 135fb | Move file pointer
2018-12-17T22:24:19.527224968Z 66 PC: 13609 | Move file pointer
2018-12-17T22:24:19.528671219Z 66 PC: 13617 | Move file pointer
2018-12-17T22:24:19.530282507Z 66 PC: 132af | Move file pointer
2018-12-17T22:24:19.532785255Z 64 PC: 131ae | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:24:19.541666158Z 62 PC: 131cd | Close file
2018-12-17T22:24:19.549474324Z 26 PC: 12c2b | Set disk transfer address
2018-12-17T22:24:19.551861344Z 79 PC: 12c30 | Find next file
2018-12-17T22:24:19.555067373Z 14 PC: 13329 | Set default drive (Drive = 'C')
2018-12-17T22:24:19.556506494Z 25 PC: 1332d | Get default drive
2018-12-17T22:24:19.558014452Z 59 PC: 13397 | Change current directory
2018-12-17T22:24:19.574671461Z 26 PC: 12c07 | Set disk transfer address
2018-12-17T22:24:19.576026885Z 78 PC: 12c13 | Find first file
2018-12-17T22:24:19.582227905Z 67 PC: 12bd6 | Get or set file attributes
2018-12-17T22:24:19.593206309Z 57 PC: 13397 | Create subdirectory
2018-12-17T22:24:19.607857072Z 58 PC: 13397 | Remove subdirectory
2018-12-17T22:24:19.619363171Z 61 PC: 1317d | Open file (Filename = 'IO.SYS')
2018-12-17T22:24:19.627317155Z 66 PC: 135fb | Move file pointer
2018-12-17T22:24:19.629292912Z 66 PC: 13609 | Move file pointer
2018-12-17T22:24:19.631427423Z 66 PC: 13617 | Move file pointer
2018-12-17T22:24:19.634606997Z 66 PC: 132af | Move file pointer
2018-12-17T22:24:19.636649293Z 64 PC: 131ae | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:24:19.644413892Z 62 PC: 131cd | Close file
2018-12-17T22:24:19.652943808Z 26 PC: 12c2b | Set disk transfer address
2018-12-17T22:24:19.654711719Z 79 PC: 12c30 | Find next file
2018-12-17T22:24:19.658311596Z 67 PC: 12bd6 | Get or set file attributes
2018-12-17T22:24:19.670001212Z 57 PC: 13397 | Create subdirectory
2018-12-17T22:24:19.685227799Z 58 PC: 13397 | Remove subdirectory
2018-12-17T22:24:19.696742891Z 61 PC: 1317d | Open file (Filename = 'MSDOS.SYS')
2018-12-17T22:24:19.704008802Z 66 PC: 135fb | Move file pointer
2018-12-17T22:24:19.706913651Z 66 PC: 13609 | Move file pointer
2018-12-17T22:24:19.708892797Z 66 PC: 13617 | Move file pointer
2018-12-17T22:24:19.711063437Z 66 PC: 132af | Move file pointer
2018-12-17T22:24:19.714177137Z 64 PC: 131ae | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:24:19.721871456Z 62 PC: 131cd | Close file
2018-12-17T22:24:19.729658243Z 26 PC: 12c2b | Set disk transfer address
2018-12-17T22:24:19.73203472Z 79 PC: 12c30 | Find next file
2018-12-17T22:24:19.735521625Z 67 PC: 12bd6 | Get or set file attributes
2018-12-17T22:24:19.746586707Z 57 PC: 13397 | Create subdirectory
2018-12-17T22:24:19.761158429Z 58 PC: 13397 | Remove subdirectory
2018-12-17T22:24:19.772768601Z 61 PC: 1317d | Open file (Filename = 'CONFIG.SYS')
2018-12-17T22:24:19.779981814Z 66 PC: 135fb | Move file pointer
2018-12-17T22:24:19.781871391Z 66 PC: 13609 | Move file pointer
2018-12-17T22:24:19.784243706Z 66 PC: 13617 | Move file pointer
2018-12-17T22:24:19.786364956Z 66 PC: 132af | Move file pointer
2018-12-17T22:24:19.788371591Z 64 PC: 131ae | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:24:19.79736051Z 62 PC: 131cd | Close file
2018-12-17T22:24:19.805813613Z 26 PC: 12c2b | Set disk transfer address
2018-12-17T22:24:19.807378646Z 79 PC: 12c30 | Find next file
2018-12-17T22:24:19.811637988Z 64 PC: 130d8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:24:19.8142891Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:19.815873918Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:24:19.818334003Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:24:19.819977829Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:19.821619285Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:19.823490354Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:19.834110955Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:24:19.835591026Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:24:19.836939199Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:24:19.838983633Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:24:19.84031837Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:24:19.841648295Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:24:19.843970034Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:24:19.845161241Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:24:19.846466951Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:24:19.848377226Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:24:19.849543793Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:24:19.858536592Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:24:19.860736007Z 37 PC: 12e11 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:24:19.862149617Z 76 PC: 12e50 | Terminate with return code (Return code = '0')