Sample viewer

vx.netlux.org/Trojan.DOS.Shock.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:48.631072495Z 48 PC: 13f24 | Get DOS version
2018-12-17T22:25:48.63330337Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.634717541Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.636054684Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.637355543Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.639345367Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.640728637Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.642022825Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.644558729Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.645981276Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.64738205Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.650796303Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.652260435Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.653693227Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.655589368Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.666224298Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.667949712Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.669674947Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.671767558Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.674081851Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.675705732Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.678441703Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.680027413Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.68161504Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.683746071Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.68536467Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.687025617Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.689485275Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.691084979Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.692651037Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.694824571Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.702698837Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.703965652Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.705910986Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.707549338Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.714954183Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.717355652Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.718732182Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.720146078Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.721993273Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.723730876Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.725162652Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.72649642Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.728980243Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.730808373Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.732610955Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.734818795Z 48 PC: 14101 | Get DOS version
2018-12-17T22:25:48.736794762Z 48 PC: 1410e | Get DOS version
2018-12-17T22:25:48.738134524Z 48 PC: 14125 | Get DOS version
2018-12-17T22:25:48.740241466Z 53 PC: 14140 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.741786871Z 53 PC: 14145 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:48.743119374Z 61 PC: 1417a | Open file (Filename = '\WINDOWS\TEMP ')