Sample viewer

vx.netlux.org/Trojan.DOS.Watching

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:50.526102326Z 53 PC: 133aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.52766665Z 53 PC: 133aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:50.529484698Z 53 PC: 133aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.530822651Z 53 PC: 133aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:50.532548314Z 53 PC: 133aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.533935887Z 53 PC: 133aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.535260046Z 53 PC: 133aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:50.536799332Z 53 PC: 133aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:50.550279687Z 53 PC: 133aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:50.557983087Z 53 PC: 133aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:50.559458352Z 53 PC: 133aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:50.561299236Z 53 PC: 133aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:50.562714403Z 53 PC: 133aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:50.564110243Z 53 PC: 133aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:50.566065485Z 53 PC: 133aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:50.567484725Z 53 PC: 133aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:50.568888486Z 53 PC: 133aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:50.576720553Z 53 PC: 133aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.578218727Z 53 PC: 133aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:50.579820831Z 37 PC: 133bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.583070271Z 37 PC: 133c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.584563644Z 37 PC: 133cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.585992977Z 37 PC: 133d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.588440376Z 68 PC: 13c79 | I/O control for devices (Set for = 's \ ')
2018-12-17T21:55:50.666169376Z 37 PC: 12dd1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.828560562Z 37 PC: 13501 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:50.830472868Z 37 PC: 13501 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:55:50.831736219Z 37 PC: 13501 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:55:50.833051776Z 37 PC: 13501 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:55:50.836339799Z 37 PC: 13501 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:55:50.838285801Z 37 PC: 13501 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:50.83980883Z 37 PC: 13501 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:55:50.84150437Z 37 PC: 13501 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:55:50.843404004Z 37 PC: 13501 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:55:50.84560326Z 37 PC: 13501 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:55:50.847733415Z 37 PC: 13501 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:55:50.84949728Z 37 PC: 13501 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:55:50.850898222Z 37 PC: 13501 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:55:50.852304946Z 37 PC: 13501 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:55:50.861003016Z 37 PC: 13501 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:55:50.862348703Z 37 PC: 13501 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:55:50.863827661Z 37 PC: 13501 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:55:50.865818654Z 37 PC: 13501 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:55:50.86701135Z 37 PC: 13501 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:55:50.86819105Z 76 PC: 13540 | Terminate with return code (Return code = '0')