Sample viewer

vx.netlux.org/Trojan.DOS.Hamara.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:18.470683075Z 48 PC: 1f99c | Get DOS version
2018-12-17T22:28:18.472459224Z 74 PC: 1f9ec | Reallocate memory
2018-12-17T22:28:18.473963377Z 48 PC: 1fa50 | Get DOS version
2018-12-17T22:28:18.475019873Z 53 PC: 1fa58 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:18.477146555Z 37 PC: 1fa6a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:18.478416231Z 53 PC: 22442 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:18.479406507Z 37 PC: 22452 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:18.481209565Z 53 PC: 22457 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:18.482357867Z 37 PC: 22467 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:18.483457438Z 53 PC: 20196 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:18.485265044Z 53 PC: 20196 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:18.486350489Z 53 PC: 20196 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:18.487499163Z 53 PC: 20196 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:18.488883491Z 53 PC: 20196 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:18.490288459Z 53 PC: 20196 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:18.491378324Z 53 PC: 20196 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:18.492432252Z 53 PC: 20196 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:18.4939013Z 53 PC: 20196 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:18.494963612Z 53 PC: 20196 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:18.495960261Z 53 PC: 20196 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:18.507976086Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:18.509633293Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:18.511425845Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:18.514001584Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:18.515608164Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:18.516816098Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:18.51914677Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:18.52058417Z 37 PC: 201c5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:18.522005803Z 37 PC: 201cc | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:18.525873123Z 37 PC: 201d1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:18.527720315Z 68 PC: 1fafb | I/O control for devices (Set for = '��P�u+�')
2018-12-17T22:28:18.529773614Z 68 PC: 1fafb | I/O control for devices (Set for = '+t���^[Z�W�@�;6D#r;�rt ��+���E��D��6D# �_�PSQRW�������Ë�3ɋ���Y����E����u���|��]����+�_ZY[X�V���\�^Ë6@#�<t�<u8\�t+t���+t����3��PSQR�')
2018-12-17T22:28:18.532047096Z 68 PC: 1fafb | I/O control for devices (Set for = '                                   ')
2018-12-17T22:28:18.534003983Z 68 PC: 1fafb | I/O control for devices (Set for = '                                 ')
2018-12-17T22:28:18.535922113Z 68 PC: 1fafb | I/O control for devices (Set for = '                                 ')
2018-12-17T22:28:18.540507585Z 53 PC: 1d288 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:18.542127588Z 53 PC: 1d295 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:18.544684238Z 53 PC: 1d2a2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:18.548241577Z 37 PC: 1d2b7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:18.550342468Z 37 PC: 1d2bf | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:18.552157045Z 37 PC: 1d2c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:18.555541683Z 53 PC: 1dd46 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:28:18.557458903Z 53 PC: 1dd53 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:28:18.559365891Z 53 PC: 1dd62 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:28:18.562043355Z 37 PC: 1dd6f | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:28:18.563380001Z 53 PC: 1dd76 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:28:18.564830886Z 37 PC: 1dd83 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:28:18.566804198Z 53 PC: 1dd8f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:28:18.572631367Z 48 PC: 1de51 | Get DOS version
2018-12-17T22:28:18.57435892Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:28:18.576512099Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:28:18.579440303Z 68 PC: 1d1fe | I/O control for devices (Set for = ' ----' '----5')
2018-12-17T22:28:18.581266957Z 68 PC: 1d1fe | I/O control for devices (Set for = '')
2018-12-17T22:28:18.583126828Z 51 PC: 1d21c | Get or set Ctrl-Break
2018-12-17T22:28:18.585409903Z 51 PC: 1d228 | Get or set Ctrl-Break
2018-12-17T22:28:18.587016947Z 72 PC: 17966 | Allocate memory
2018-12-17T22:28:18.589627512Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:28:18.592635183Z 72 PC: 17966 | Allocate memory
2018-12-17T22:28:18.596448088Z 37 PC: 18e11 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:28:18.603873561Z 73 PC: 17966 | Release memory
2018-12-17T22:28:18.607809757Z 74 PC: 1bce3 | Reallocate memory
2018-12-17T22:28:18.610398264Z 51 PC: 1d233 | Get or set Ctrl-Break
2018-12-17T22:28:18.611842663Z 37 PC: 1d4b5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:18.614491282Z 37 PC: 1d4bf | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:18.618928975Z 37 PC: 1d4c9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:18.620315844Z 53 PC: 1b710 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:28:18.622226224Z 53 PC: 1b71d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:28:18.624130332Z 53 PC: 1b72a | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:28:18.626102979Z 37 PC: 1b745 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:28:18.629072769Z 53 PC: 1b74d | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:28:18.630690742Z 37 PC: 1b75a | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:28:18.632763503Z 53 PC: 1b761 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:28:18.635282181Z 37 PC: 1b76e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:28:18.637209298Z 37 PC: 1b778 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:28:18.639228289Z 37 PC: 1b783 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:28:18.64194167Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:28:18.643370273Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:28:18.644706882Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:28:18.647400449Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:28:18.649242242Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:28:18.650666564Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:28:18.654160847Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:28:18.655586568Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:28:18.656903386Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:28:18.658782028Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:28:18.660131308Z 37 PC: 201e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:28:18.661389413Z 37 PC: 22476 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:28:18.662968123Z 37 PC: 1fbac | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:18.665180637Z 41 PC: 1f893 | Parse filename
2018-12-17T22:28:18.66685292Z 41 PC: 1f895 | Parse filename
2018-12-17T22:28:18.669470113Z 41 PC: 1f89a | Parse filename
2018-12-17T22:28:18.671932671Z 75 PC: 1f8b0 | Execute program
2018-12-17T22:28:18.700206162Z 80 PC: 27399 | Set current PSP
2018-12-17T22:28:18.702529321Z 48 PC: 2739e | Get DOS version
2018-12-17T22:28:18.704779501Z 99 PC: 2db80 | Get DBCS lead byte table pointer
2018-12-17T22:28:18.70840001Z 101 PC: 27424 | Get extended country info
2018-12-17T22:28:18.712294644Z 99 PC: 2742a | Get DBCS lead byte table pointer
2018-12-17T22:28:18.714445531Z 74 PC: 2748c | Reallocate memory
2018-12-17T22:28:18.716742976Z 25 PC: 274c3 | Get default drive
2018-12-17T22:28:18.719505387Z 37 PC: 26f83 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:28:18.72166247Z 37 PC: 26f8a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:18.723545267Z 37 PC: 26f91 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:18.73095988Z 74 PC: 2612c | Reallocate memory
2018-12-17T22:28:18.734397001Z 72 PC: 2616d | Allocate memory
2018-12-17T22:28:18.736658295Z 72 PC: 261a5 | Allocate memory
2018-12-17T22:28:18.739345939Z 72 PC: 261ad | Allocate memory