Sample viewer

vx.netlux.org/Trojan.DOS.Lsdex

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:02.474315365Z 53 PC: 13586 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:02.47584905Z 53 PC: 13586 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:29:02.476925065Z 53 PC: 13586 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:29:02.477982669Z 53 PC: 13586 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:02.480112809Z 53 PC: 13586 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:02.481236056Z 53 PC: 13586 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:29:02.482270614Z 53 PC: 13586 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:29:02.484266479Z 53 PC: 13586 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:29:02.485331184Z 53 PC: 13586 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:29:02.486366489Z 53 PC: 13586 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:29:02.488437258Z 53 PC: 13586 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:29:02.489564658Z 53 PC: 13586 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:29:02.490659315Z 53 PC: 13586 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:29:02.492641067Z 53 PC: 13586 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:29:02.493772021Z 53 PC: 13586 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:29:02.494870974Z 53 PC: 13586 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:29:02.49594456Z 53 PC: 13586 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:02.49776684Z 53 PC: 13586 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:29:02.505668217Z 37 PC: 1359b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:02.506943061Z 37 PC: 135a3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:02.509151978Z 37 PC: 135ab | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:02.510857156Z 37 PC: 135b3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:02.512317623Z 68 PC: 13c47 | I/O control for devices (Set for = '')
2018-12-17T22:29:02.56832339Z 37 PC: 12fb7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:29:02.575480205Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.581629725Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.592041469Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.59577848Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.599660751Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.604520342Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.609868507Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.615508495Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.618197513Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.621205143Z 67 PC: 12e6c | Get or set file attributes
2018-12-17T22:29:02.67520173Z 37 PC: 13695 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:29:02.677593579Z 37 PC: 13695 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:29:02.679028303Z 37 PC: 13695 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:29:02.680342336Z 37 PC: 13695 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:29:02.682042229Z 37 PC: 13695 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:02.683676087Z 37 PC: 13695 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:29:02.685269556Z 37 PC: 13695 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:29:02.687147145Z 37 PC: 13695 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:29:02.689917577Z 37 PC: 13695 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:29:02.691091794Z 37 PC: 13695 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:29:02.692710355Z 37 PC: 13695 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:29:02.695075145Z 37 PC: 13695 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:29:02.697059504Z 37 PC: 13695 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:29:02.698517026Z 37 PC: 13695 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:29:02.700703126Z 37 PC: 13695 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:29:02.702509777Z 37 PC: 13695 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:29:02.705185923Z 37 PC: 13695 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:29:02.707242526Z 37 PC: 13695 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:29:02.708619821Z 76 PC: 136d4 | Terminate with return code (Return code = '0')