Sample viewer

vx.netlux.org/Trojan.DOS.Futs

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:38.948884719Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:30:38.951644175Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:38.95343942Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:38.955254941Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:38.958071942Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:38.959843385Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:30:38.961560084Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:30:38.964338774Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:30:38.966091078Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:30:38.96782118Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:30:38.97050076Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:30:38.972449137Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:30:38.974186486Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:30:38.976963424Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:30:38.978801053Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:30:38.980512639Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:30:38.98251408Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:38.985026902Z 53 PC: 38e0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:30:38.988170456Z 37 PC: 38e27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:30:38.989755645Z 37 PC: 38e2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:39.001827836Z 37 PC: 38e37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:30:39.003986629Z 68 PC: 3a0ce | I/O control for devices
2018-12-17T22:30:39.117302196Z 37 PC: 38831 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:30:39.129767815Z 48 PC: 39a16 | Get DOS version
2018-12-17T22:30:39.131904122Z 44 PC: 3a566 | Get time 0x3a566: mov word ptr [0x4306], cx
0x3a56a: mov word ptr [0x4308], dx
0x3a56e: retf
0x3a56f: mov cx, di
0x3a571: mov si, 0xa
0x3a574: mov bx, dx
0x3a576: or bx, bx
0x3a578: jns 0x3a58b
0x3a57a: neg bx
0x3a57c: neg ax
0x3a57e: sbb bx, 0
0x3a581: call 0x3a58b
0x3a584: dec di
0x3a585: mov byte ptr es:[di], 0x2d
0x3a589: inc cx
0x3a58a: ret
0x3a58b: xor dx, dx
0x3a58d: xchg ax, bx
0x3a58e: div si
0x3a590: xchg ax, bx
2018-12-17T22:30:39.139608608Z 67 PC: 38351 | Get or set file attributes
2018-12-17T22:30:39.166639312Z 61 PC: 39854 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:30:39.1730292Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.189372336Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.196793028Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.203164673Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.214495387Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.224721765Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.234243913Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)
2018-12-17T22:30:39.243679991Z 63 PC: 39927 | Read file or device (Read 206848 bytes on handle 5)