Sample viewer

vx.netlux.org/Trojan.DOS.Shar.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:25.598096777Z 48 PC: 15e3c | Get DOS version
2018-12-17T22:30:25.599735761Z 74 PC: 15e8c | Reallocate memory
2018-12-17T22:30:25.601501896Z 48 PC: 15ef0 | Get DOS version
2018-12-17T22:30:25.602659254Z 53 PC: 15ef8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:25.605515197Z 37 PC: 15f0a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:25.606758421Z 68 PC: 15f9b | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T22:30:25.608110407Z 68 PC: 15f9b | I/O control for devices
2018-12-17T22:30:25.610530226Z 68 PC: 15f9b | I/O control for devices
2018-12-17T22:30:25.611884802Z 68 PC: 15f9b | I/O control for devices
2018-12-17T22:30:25.613231335Z 68 PC: 15f9b | I/O control for devices
2018-12-17T22:30:25.614878072Z 53 PC: 147b4 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:25.626641855Z 53 PC: 147c1 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:30:25.627924435Z 53 PC: 147ce | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:25.628953131Z 37 PC: 147e3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:25.630425175Z 37 PC: 147eb | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:30:25.63170339Z 37 PC: 147f3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:25.633237222Z 53 PC: 15272 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:30:25.636002631Z 53 PC: 1527f | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:30:25.637533582Z 53 PC: 1528e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:30:25.639001214Z 37 PC: 1529b | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:30:25.640938483Z 53 PC: 152a2 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:30:25.642546851Z 37 PC: 152af | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:30:25.644219715Z 53 PC: 152bb | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:30:25.649007803Z 48 PC: 1537d | Get DOS version
2018-12-17T22:30:25.650344378Z 74 PC: 1347f | Reallocate memory
2018-12-17T22:30:25.652668332Z 74 PC: 1347f | Reallocate memory
2018-12-17T22:30:25.655344007Z 68 PC: 1472a | I/O control for devices (Set for = 't /add')
2018-12-17T22:30:25.657375266Z 68 PC: 1472a | I/O control for devices (Set for = '')
2018-12-17T22:30:25.659226074Z 51 PC: 14748 | Get or set Ctrl-Break
2018-12-17T22:30:25.662170916Z 51 PC: 14754 | Get or set Ctrl-Break
2018-12-17T22:30:25.665426927Z 74 PC: 1347f | Reallocate memory
2018-12-17T22:30:25.667479021Z 51 PC: 1475f | Get or set Ctrl-Break
2018-12-17T22:30:25.669447664Z 53 PC: 12eac | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:30:25.671358097Z 53 PC: 12eb9 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:30:25.672972975Z 53 PC: 12ec6 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:30:25.674922209Z 37 PC: 12ee1 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:30:25.676590888Z 53 PC: 12ee9 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:30:25.677763496Z 37 PC: 12ef6 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:30:25.683339037Z 53 PC: 12efd | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:30:25.684673438Z 37 PC: 12f0a | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:30:25.685746623Z 37 PC: 12f14 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:30:25.687748Z 37 PC: 12f1f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:30:25.688852501Z 37 PC: 1604c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:30:25.692718036Z 41 PC: 15c4f | Parse filename
2018-12-17T22:30:25.69509427Z 41 PC: 15c51 | Parse filename
2018-12-17T22:30:25.696378519Z 41 PC: 15c56 | Parse filename
2018-12-17T22:30:25.69772266Z 75 PC: 15c6c | Execute program
2018-12-17T22:30:25.719833122Z 80 PC: 18e49 | Set current PSP
2018-12-17T22:30:25.720712124Z 48 PC: 18e4e | Get DOS version
2018-12-17T22:30:25.722100439Z 99 PC: 1f630 | Get DBCS lead byte table pointer
2018-12-17T22:30:25.724903008Z 101 PC: 18ed4 | Get extended country info
2018-12-17T22:30:25.726533227Z 99 PC: 18eda | Get DBCS lead byte table pointer
2018-12-17T22:30:25.72788137Z 74 PC: 18f3c | Reallocate memory
2018-12-17T22:30:25.72983197Z 25 PC: 18f73 | Get default drive
2018-12-17T22:30:25.73076213Z 37 PC: 18a33 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:30:25.731648354Z 37 PC: 18a3a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:25.732897803Z 37 PC: 18a41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:25.737652574Z 74 PC: 17bdc | Reallocate memory
2018-12-17T22:30:25.740110401Z 72 PC: 17c1d | Allocate memory
2018-12-17T22:30:25.743328014Z 72 PC: 17c55 | Allocate memory
2018-12-17T22:30:25.74571067Z 72 PC: 17c5d | Allocate memory