Sample viewer

vx.netlux.org/Trojan.DOS.DelWin.l

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:41.526137754Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:41.527995033Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:41.529317979Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:41.531015217Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:41.532504676Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:41.53408761Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:41.535431968Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:41.536895834Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:41.53881903Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:41.540443138Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:41.54243129Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:41.544146571Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:41.545363461Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:41.546575848Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:41.548207931Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:41.549605544Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:41.550911997Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:41.554558613Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:41.55596393Z 53 PC: 12d1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:41.557613367Z 37 PC: 12d2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:41.559542968Z 37 PC: 12d37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:41.560715747Z 37 PC: 12d3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:41.561873854Z 37 PC: 12d47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:41.563778358Z 68 PC: 135bc | I/O control for devices (Set for = '����t �Y��{t�����VWPQ�f��c���f��|')
2018-12-17T22:32:41.565983905Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:41.567745466Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:32:41.569467279Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:41.572171479Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:32:41.573521797Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:41.578666714Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:32:41.581460679Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:41.583203884Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:41.584390586Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:41.585891521Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:41.587173814Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:41.58849583Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:41.589950323Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:41.592140768Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:32:41.593464449Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:41.594923997Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:32:41.597022253Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:41.598350342Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:32:41.59958Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:41.602014819Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:32:41.603160473Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:41.604250873Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:32:41.605910127Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:41.607077497Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:32:41.608154546Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:41.612646989Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:32:41.613777006Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:41.614700796Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:32:41.616467054Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:41.617595807Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:32:41.61874509Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:41.619962818Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:32:41.621348159Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:41.622511287Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:32:41.62349683Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:41.624828126Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:32:41.625906736Z 53 PC: 12c98 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:41.626967015Z 37 PC: 12ca1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:32:41.629033741Z 41 PC: 12c4f | Parse filename
2018-12-17T22:32:41.630368646Z 41 PC: 12c5d | Parse filename
2018-12-17T22:32:41.631444592Z 75 PC: 12c68 | Execute program
2018-12-17T22:32:41.648541698Z 80 PC: 170f9 | Set current PSP
2018-12-17T22:32:41.64991405Z 48 PC: 170fe | Get DOS version
2018-12-17T22:32:41.65177938Z 99 PC: 1d8e0 | Get DBCS lead byte table pointer
2018-12-17T22:32:41.655425543Z 101 PC: 17184 | Get extended country info
2018-12-17T22:32:41.657092711Z 99 PC: 1718a | Get DBCS lead byte table pointer
2018-12-17T22:32:41.658588659Z 74 PC: 171ec | Reallocate memory
2018-12-17T22:32:41.660859745Z 25 PC: 17223 | Get default drive
2018-12-17T22:32:41.662123153Z 37 PC: 16ce3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:32:41.663911026Z 37 PC: 16cea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:32:41.665914346Z 37 PC: 16cf1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:32:41.670878017Z 74 PC: 15e8c | Reallocate memory
2018-12-17T22:32:41.672454031Z 72 PC: 15ecd | Allocate memory
2018-12-17T22:32:41.674840931Z 72 PC: 15f05 | Allocate memory
2018-12-17T22:32:41.676898227Z 72 PC: 15f0d | Allocate memory