Sample viewer

vx.netlux.org/Trojan.DOS.Ily

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:10.066496311Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:10.06884261Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:10.070334578Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:10.071964025Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:10.074353171Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:10.075519183Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:10.076684775Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:10.078693167Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:10.081660608Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:10.084011073Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:10.086812451Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:10.088713793Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:10.09022676Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:10.092023431Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:10.094390489Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:10.096461037Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:10.098578606Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:10.100683446Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:10.101780834Z 53 PC: 13aaa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:10.102889196Z 37 PC: 13abf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:10.110812933Z 37 PC: 13ac7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:10.112516764Z 37 PC: 13acf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:10.114481275Z 37 PC: 13ad7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:10.117307559Z 68 PC: 14987 | I/O control for devices (Set for = 'G��4� ')
2018-12-17T22:32:10.26170183Z 64 PC: 1412b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:32:10.263855695Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:10.266004798Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:10.267505302Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:10.26897671Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:10.271500875Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:10.273558941Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:10.275306051Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:10.27730552Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:10.278792499Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:10.280210666Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:10.282416342Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:10.283823339Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:10.285215746Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:10.28702997Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:10.288753577Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:10.28991007Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:10.291836582Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:10.292966223Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:10.294112282Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:10.296005516Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.298401018Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.300747158Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.303322042Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.306219546Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.308558298Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.311125359Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.31387547Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.316074416Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.318236811Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.320839107Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.322903574Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.325644084Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.328782251Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.331095949Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.333439921Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.336612976Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.338907685Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.341211085Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.344448118Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.346735987Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.349051648Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.352392595Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.356444918Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.358374669Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.361023866Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.362977067Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.364836972Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.367839096Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.369737528Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.371581028Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.374072907Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.376420794Z 6 PC: 13c88 | Direct console I/O
2018-12-17T22:32:10.379795948Z 76 PC: 13c40 | Terminate with return code (Return code = '200')