Sample viewer

vx.netlux.org/Trojan.DOS.Aid

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:53.624989803Z 48 PC: 16eac | Get DOS version
2018-12-17T22:28:53.629429259Z 74 PC: 16efc | Reallocate memory
2018-12-17T22:28:53.631085383Z 48 PC: 16f60 | Get DOS version
2018-12-17T22:28:53.632134531Z 53 PC: 16f68 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:53.634123948Z 37 PC: 16f7a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:53.638825069Z 68 PC: 1700b | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T22:28:53.647760961Z 68 PC: 1700b | I/O control for devices
2018-12-17T22:28:53.649324574Z 68 PC: 1700b | I/O control for devices
2018-12-17T22:28:53.661976093Z 68 PC: 1700b | I/O control for devices
2018-12-17T22:28:53.664122714Z 68 PC: 1700b | I/O control for devices
2018-12-17T22:28:53.666247641Z 53 PC: 14b06 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:53.66853687Z 53 PC: 14b13 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:53.669950047Z 53 PC: 14b20 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:53.671318024Z 37 PC: 14b35 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:28:53.674020112Z 37 PC: 14b3d | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:28:53.675150421Z 37 PC: 14b45 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:53.676403754Z 53 PC: 155c4 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:28:53.678502341Z 53 PC: 155d1 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:28:53.679603736Z 53 PC: 155e0 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:28:53.680683456Z 37 PC: 155ed | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:28:53.682721981Z 53 PC: 155f4 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:28:53.684311005Z 37 PC: 15601 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:28:53.685811533Z 53 PC: 1560d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:28:53.690223914Z 48 PC: 156cf | Get DOS version
2018-12-17T22:28:53.691503831Z 68 PC: 14a7c | I/O control for devices (Set for = '>>>� ')
2018-12-17T22:28:53.692836772Z 68 PC: 14a7c | I/O control for devices (Set for = '')
2018-12-17T22:28:53.694979476Z 51 PC: 14a9a | Get or set Ctrl-Break
2018-12-17T22:28:53.697503622Z 51 PC: 14aa6 | Get or set Ctrl-Break
2018-12-17T22:28:53.705451488Z 26 PC: 12bf5 | Set disk transfer address
2018-12-17T22:28:53.706766546Z 78 PC: 12bfc | Find first file
2018-12-17T22:28:53.713289285Z 65 PC: 12b73 | Delete file (Filename = 'C:\IO.SYS')
2018-12-17T22:28:54.06555754Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.068925842Z 65 PC: 12b73 | Delete file (Filename = 'C:\MSDOS.SYS')
2018-12-17T22:28:54.080887497Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.087160782Z 65 PC: 12b73 | Delete file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:28:54.097542847Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.101993149Z 65 PC: 12b73 | Delete file (Filename = 'C:\CONFIG.SYS')
2018-12-17T22:28:54.112684814Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.116178434Z 65 PC: 12b73 | Delete file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:28:54.134980233Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.138271755Z 26 PC: 12bf5 | Set disk transfer address
2018-12-17T22:28:54.140112543Z 78 PC: 12bfc | Find first file
2018-12-17T22:28:54.149946401Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:28:54.161444441Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.164761422Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T22:28:54.17581027Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.178822179Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\COUNTRY.SYS')
2018-12-17T22:28:54.189998986Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.193519041Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\COUNTRY.TXT')
2018-12-17T22:28:54.204648702Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.20786384Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T22:28:54.219230885Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.222970253Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\DOSSETUP.INI')
2018-12-17T22:28:54.233660641Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.237800165Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\DRVSPACE.BIN')
2018-12-17T22:28:54.247832095Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.251904765Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T22:28:54.26050787Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.262946314Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T22:28:54.270547123Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.273972444Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T22:28:54.281977316Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.285212337Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:28:54.294972663Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.29779461Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T22:28:54.306381982Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.310453408Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\KEYBOARD.SYS')
2018-12-17T22:28:54.317532494Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.322093683Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\MEM.EXE')
2018-12-17T22:28:54.33341974Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.336559516Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\NLSFUNC.EXE')
2018-12-17T22:28:54.347137915Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.351545572Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\README.TXT')
2018-12-17T22:28:54.363017583Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.366141935Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\NETWORKS.TXT')
2018-12-17T22:28:54.377379597Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.380448154Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\QBASIC.EXE')
2018-12-17T22:28:54.391897841Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.396318582Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\REPLACE.EXE')
2018-12-17T22:28:54.406988321Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.410020412Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\RESTORE.EXE')
2018-12-17T22:28:54.420768082Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.424081509Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\SCANDISK.EXE')
2018-12-17T22:28:54.434891444Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.438508279Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\SCANDISK.INI')
2018-12-17T22:28:54.450897071Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.454351337Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\SETUP.EXE')
2018-12-17T22:28:54.465060994Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.468396054Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\SYS.COM')
2018-12-17T22:28:54.479613967Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.483525727Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\XCOPY.EXE')
2018-12-17T22:28:54.495179939Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.498309065Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\DEFRAG.EXE')
2018-12-17T22:28:54.510990486Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.514581217Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\DEFRAG.HLP')
2018-12-17T22:28:54.525069689Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.52809552Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\EGA.CPI')
2018-12-17T22:28:54.538852243Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.541845035Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\EGA2.CPI')
2018-12-17T22:28:54.552570492Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.555860182Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\EGA3.CPI')
2018-12-17T22:28:54.566457017Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.569576315Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\EMM386.EXE')
2018-12-17T22:28:54.581627177Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.584723846Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\ISO.CPI')
2018-12-17T22:28:54.595097687Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.598688555Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\KEYBRD2.SYS')
2018-12-17T22:28:54.609189492Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.612166649Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\MSCDEX.EXE')
2018-12-17T22:28:54.622787644Z 79 PC: 12b79 | Find next file
2018-12-17T22:28:54.625839218Z 65 PC: 12b73 | Delete file (Filename = 'C:\DOS\QBASIC.INI')
2018-12-17T22:28:54.637558532Z 79 PC: 12b79 | Find next file