Sample viewer

vx.netlux.org/Trojan.DOS.Ciko

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:27.078888866Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:27.08107884Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:27.082398684Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:27.083603411Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:27.086212935Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:27.087777858Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:27.089300614Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:27.090991863Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:27.09326998Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:27.094769229Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:27.096224503Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:27.098671087Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:27.099837894Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:27.101022398Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:27.102846287Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:27.104984422Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:27.106395573Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:27.108618306Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:27.112212592Z 53 PC: 1bc2a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:27.119446569Z 37 PC: 1bc3f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:27.121940463Z 37 PC: 1bc47 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:27.123702967Z 37 PC: 1bc4f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:27.125356022Z 37 PC: 1bc57 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:27.129884003Z 68 PC: 1c97c | I/O control for devices (Set for = '')
2018-12-17T22:27:27.230106652Z 37 PC: 1b391 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:27.232442577Z 67 PC: 1b991 | Get or set file attributes
2018-12-17T22:27:27.239452753Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.24542197Z 61 PC: 1c3cb | Open file (Filename = 'c:\(c)IkO')
2018-12-17T22:27:27.251412261Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.273358188Z 61 PC: 1c960 | Open file (Filename = 'c:\msdos.sys')
2018-12-17T22:27:27.279985507Z 63 PC: 1bff1 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:27:27.289673602Z 62 PC: 1c062 | Close file
2018-12-17T22:27:27.297086347Z 67 PC: 1b991 | Get or set file attributes
2018-12-17T22:27:27.344945114Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.351881259Z 61 PC: 1c3cb | Open file (Filename = 'c:\windows\msemap.ini')
2018-12-17T22:27:27.359559687Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.367236308Z 60 PC: 1c960 | Create or truncate file
2018-12-17T22:27:27.716257081Z 68 PC: 1c97c | I/O control for devices (Set for = '')
2018-12-17T22:27:27.720323898Z 64 PC: 1c023 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:27:27.729693705Z 62 PC: 1c062 | Close file
2018-12-17T22:27:27.738051244Z 61 PC: 1c3cb | Open file (Filename = 'c:\windows\msemap.ini')
2018-12-17T22:27:27.746373423Z 66 PC: 1ca7b | Move file pointer
2018-12-17T22:27:27.750561206Z 66 PC: 1ca89 | Move file pointer
2018-12-17T22:27:27.765931941Z 66 PC: 1ca97 | Move file pointer
2018-12-17T22:27:27.768460461Z 62 PC: 1c41b | Close file
2018-12-17T22:27:27.772776384Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.779169514Z 67 PC: 1b991 | Get or set file attributes
2018-12-17T22:27:27.785187144Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.792568715Z 61 PC: 1c3cb | Open file (Filename = '\m.CoM')
2018-12-17T22:27:27.799103386Z 67 PC: 1b9b8 | Get or set file attributes
2018-12-17T22:27:27.81873078Z 60 PC: 1c3cb | Create or truncate file
2018-12-17T22:27:27.837967378Z 64 PC: 1c49e | Write file or device (Write 29895 bytes on handle 5)
2018-12-17T22:27:27.853462921Z 62 PC: 1c41b | Close file
2018-12-17T22:27:27.863973243Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:27.866071311Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:27.867254465Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:27.868410003Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:27.870570446Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:27.871724918Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:27.879632453Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:27.881430314Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:27.883385365Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:27.884872635Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:27.8871208Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:27.88898003Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:27.890426764Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:27.893050052Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:27.894822477Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:27.896242211Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:27.897876142Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:27.900135357Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:27.901533779Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:27.90298619Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:27.905382267Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:27.906806267Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:27.908965002Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:27.911425388Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:27.912840174Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:27.914291976Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:27.916737048Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:27.918196279Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:27.9196058Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:27.921912116Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:27.923689675Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:27.925158398Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:27.927329202Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:27.929139122Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:27.930559501Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:27.932738913Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:27.934494492Z 53 PC: 1bb9e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:27.93591144Z 37 PC: 1bba7 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:27.939004962Z 41 PC: 1bb55 | Parse filename
2018-12-17T22:27:27.941002511Z 41 PC: 1bb63 | Parse filename
2018-12-17T22:27:27.94264821Z 75 PC: 1bb6e | Execute program
2018-12-17T22:27:27.965228384Z 80 PC: 206f9 | Set current PSP
2018-12-17T22:27:27.96657822Z 48 PC: 206fe | Get DOS version
2018-12-17T22:27:27.968334021Z 99 PC: 26ee0 | Get DBCS lead byte table pointer
2018-12-17T22:27:27.971374383Z 101 PC: 20784 | Get extended country info
2018-12-17T22:27:27.976686476Z 99 PC: 2078a | Get DBCS lead byte table pointer
2018-12-17T22:27:27.978043695Z 74 PC: 207ec | Reallocate memory
2018-12-17T22:27:27.979975123Z 25 PC: 20823 | Get default drive
2018-12-17T22:27:27.981690315Z 37 PC: 202e3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:27:27.983074099Z 37 PC: 202ea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:27.984637349Z 37 PC: 202f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:27.989468761Z 74 PC: 1f48c | Reallocate memory
2018-12-17T22:27:27.991994768Z 72 PC: 1f4cd | Allocate memory
2018-12-17T22:27:27.993913598Z 72 PC: 1f505 | Allocate memory
2018-12-17T22:27:27.996594129Z 72 PC: 1f50d | Allocate memory