Sample viewer

vx.netlux.org/Trojan.DOS.RickDogg

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:31.194609389Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:31.198962469Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:31.200762552Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:31.202311778Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:31.204718204Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:31.205880504Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:31.206924288Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:31.209154369Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:31.210432967Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:31.211524035Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:31.217319998Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:31.218435136Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:31.21950277Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:31.220979702Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:31.22202665Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:31.223170757Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:31.229378603Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:31.237737117Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:31.238782327Z 53 PC: 16da2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:31.240060426Z 37 PC: 16db7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:31.24114952Z 37 PC: 16dbf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:31.241894866Z 37 PC: 16dc7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:31.242822383Z 37 PC: 16dcf | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:31.246147132Z 68 PC: 173a4 | I/O control for devices (Set for = '')
2018-12-17T22:27:31.299982821Z 37 PC: 167c5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:31.303232705Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:27:31.304194749Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:27:31.305179461Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:27:31.306614218Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:31.308030386Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:27:31.309127159Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:31.31076586Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:27:31.311816691Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:27:31.312785006Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:27:31.313818468Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:27:31.315125181Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:27:31.316083865Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:27:31.31704762Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:27:31.318490622Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:27:31.319513445Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:27:31.320639977Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:27:31.324925942Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:27:31.326207001Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:27:31.327201585Z 37 PC: 16eb6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:27:31.328446886Z 76 PC: 16ef5 | Terminate with return code (Return code = '0')