Sample viewer

vx.netlux.org/Trojan.DOS.SlowDown

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:40.886839205Z 53 PC: 13926 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:40.889154083Z 53 PC: 13926 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:40.891474634Z 53 PC: 13926 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:40.893816141Z 53 PC: 13926 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:40.89681974Z 53 PC: 13926 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:40.899458399Z 53 PC: 13926 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:40.902843043Z 53 PC: 13926 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:40.905576989Z 53 PC: 13926 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:40.907642321Z 53 PC: 13926 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:40.909979291Z 53 PC: 13926 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:40.912547369Z 53 PC: 13926 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:40.915070234Z 53 PC: 13926 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:40.917689349Z 53 PC: 13926 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:40.920274558Z 53 PC: 13926 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:40.922746109Z 53 PC: 13926 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:40.925145073Z 53 PC: 13926 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:40.927479568Z 53 PC: 13926 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:40.929821785Z 53 PC: 13926 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:40.931255659Z 37 PC: 1393b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:40.932801876Z 37 PC: 13943 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:40.93447787Z 37 PC: 1394b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:40.936393328Z 37 PC: 13953 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:40.93876647Z 68 PC: 143a3 | I/O control for devices (Set for = '')
2018-12-17T22:32:40.941076076Z 37 PC: 13deb | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:40.942315126Z 37 PC: 13deb | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:40.944492165Z 37 PC: 13deb | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:40.945881631Z 37 PC: 13deb | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:40.947323303Z 37 PC: 13deb | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:40.949245838Z 37 PC: 13deb | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:40.950575143Z 37 PC: 13deb | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:40.951904107Z 37 PC: 13deb | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:40.953998388Z 37 PC: 13deb | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:40.955416198Z 37 PC: 13deb | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:40.956788374Z 37 PC: 13df2 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:40.959899285Z 37 PC: 13df9 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:40.962200355Z 37 PC: 13e00 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:41.051123579Z 37 PC: 13297 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:41.05350375Z 44 PC: 140b1 | Get time 0x140b1: mov word ptr [0x38], cx
0x140b5: mov word ptr [0x3a], dx
0x140b9: retf
0x140ba: push di
0x140bb: cld
0x140bc: mov bx, ax
0x140be: or dx, dx
0x140c0: jge 0x140cf
0x140c2: not bx
0x140c4: not dx
0x140c6: add bx, 1
0x140c9: adc dx, 0
0x140cc: mov al, 0x2d
0x140ce: stosb byte ptr es:[di], al
0x140cf: mov si, 0x82c
0x140d2: mov cl, 9
0x140d4: cmp dx, word ptr cs:[si + 2]
0x140d8: jb 0x140e1
0x140da: ja 0x140e8
0x140dc: cmp bx, word ptr cs:[si]
2018-12-17T22:32:41.061574282Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:41.063267949Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:41.064933442Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:41.067389353Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:41.068992056Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:41.070589333Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:41.073232702Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:41.074912104Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:41.076498239Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:41.079173054Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:41.080763584Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:41.082434148Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:41.08474471Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:41.086148855Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:41.087479131Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:41.09024615Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:41.104198382Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:41.105480579Z 37 PC: 13a35 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:41.106799848Z 76 PC: 13a74 | Terminate with return code (Return code = '2')