Sample viewer

vx.netlux.org/Trojan.DOS.Direxe.d

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:01.573793416Z 53 PC: 13636 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:01.576161567Z 53 PC: 13636 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:01.577421828Z 53 PC: 13636 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:01.578621726Z 53 PC: 13636 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:01.580161626Z 53 PC: 13636 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:01.581239095Z 53 PC: 13636 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:01.582306156Z 53 PC: 13636 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:01.584124921Z 53 PC: 13636 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:01.586255834Z 53 PC: 13636 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:01.58805064Z 53 PC: 13636 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:01.589842808Z 53 PC: 13636 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:01.59131936Z 53 PC: 13636 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:01.592513291Z 53 PC: 13636 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:01.593932308Z 53 PC: 13636 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:01.595343023Z 53 PC: 13636 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:01.596413364Z 53 PC: 13636 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:01.597542494Z 53 PC: 13636 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:01.59939938Z 53 PC: 13636 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:01.600857513Z 37 PC: 1364b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:01.602348837Z 37 PC: 13653 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:01.604809061Z 37 PC: 1365b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:01.606004301Z 37 PC: 13663 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:01.607453959Z 68 PC: 13cf7 | I/O control for devices (Set for = '')
2018-12-17T22:27:01.614243932Z 48 PC: 142ea | Get DOS version
2018-12-17T22:27:01.616187276Z 48 PC: 142ea | Get DOS version
2018-12-17T22:27:01.618185936Z 61 PC: 140aa | Open file (Filename = 'c:\windows\win.com')
2018-12-17T22:27:01.629316268Z 67 PC: 134a6 | Get or set file attributes
2018-12-17T22:27:01.977676774Z 62 PC: 140fa | Close file
2018-12-17T22:27:01.979685829Z 61 PC: 140aa | Open file (Filename = 'c:\windows\win.mtx')
2018-12-17T22:27:01.990872928Z 86 PC: 142b5 | Rename file
2018-12-17T22:27:02.004327713Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:02.005448673Z 37 PC: 134cc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:02.007527607Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:02.008633241Z 37 PC: 134cc | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:02.009698649Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:02.010973855Z 37 PC: 134cc | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:02.012860974Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:02.014385179Z 37 PC: 134cc | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:02.015568542Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:02.016836695Z 37 PC: 134cc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:02.017998892Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:02.019156458Z 37 PC: 134cc | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:02.020875038Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:02.021944459Z 37 PC: 134cc | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:02.022953242Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:02.024800097Z 37 PC: 134cc | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:02.02580998Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:02.026824748Z 37 PC: 134cc | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:02.028248206Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:02.029407737Z 37 PC: 134cc | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:02.030520119Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:02.032260845Z 37 PC: 134cc | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:02.033296041Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:02.034322014Z 37 PC: 134cc | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:02.035671459Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:02.036665197Z 37 PC: 134cc | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:02.037626526Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:02.039036161Z 37 PC: 134cc | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:02.040000829Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:02.041012251Z 37 PC: 134cc | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:02.042422075Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:02.043479174Z 37 PC: 134cc | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:02.044709362Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:02.046543898Z 37 PC: 134cc | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:02.047589201Z 53 PC: 134c3 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:02.048668434Z 37 PC: 134cc | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:02.050308154Z 48 PC: 142ea | Get DOS version
2018-12-17T22:27:02.05173078Z 41 PC: 1354b | Parse filename
2018-12-17T22:27:02.053006188Z 41 PC: 13559 | Parse filename
2018-12-17T22:27:02.054847883Z 75 PC: 13564 | Execute program
2018-12-17T22:27:02.074430754Z 80 PC: 1a5b9 | Set current PSP
2018-12-17T22:27:02.075220217Z 48 PC: 1a5be | Get DOS version
2018-12-17T22:27:02.077789186Z 99 PC: 20da0 | Get DBCS lead byte table pointer
2018-12-17T22:27:02.080669945Z 101 PC: 1a644 | Get extended country info
2018-12-17T22:27:02.082345284Z 99 PC: 1a64a | Get DBCS lead byte table pointer
2018-12-17T22:27:02.084331974Z 74 PC: 1a6ac | Reallocate memory
2018-12-17T22:27:02.085727583Z 25 PC: 1a6e3 | Get default drive
2018-12-17T22:27:02.086810832Z 37 PC: 1a1a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:27:02.089733487Z 37 PC: 1a1aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:02.090899995Z 37 PC: 1a1b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:02.095253493Z 74 PC: 1934c | Reallocate memory
2018-12-17T22:27:02.097197865Z 72 PC: 1938d | Allocate memory
2018-12-17T22:27:02.098775604Z 72 PC: 193c5 | Allocate memory
2018-12-17T22:27:02.100458664Z 72 PC: 193cd | Allocate memory