Sample viewer

vx.netlux.org/Trojan.DOS.GDE.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:33.368186027Z 53 PC: 13412 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:33.370136847Z 53 PC: 13412 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:33.3715528Z 53 PC: 13412 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:33.372877966Z 53 PC: 13412 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:33.37446207Z 53 PC: 13412 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:33.376959296Z 53 PC: 13412 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:33.378089829Z 53 PC: 13412 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:33.379187273Z 53 PC: 13412 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:33.381260622Z 53 PC: 13412 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:33.382336121Z 53 PC: 13412 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:33.383390041Z 53 PC: 13412 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:33.386268558Z 53 PC: 13412 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:33.387372721Z 53 PC: 13412 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:33.414362149Z 53 PC: 13412 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:33.416108801Z 53 PC: 13412 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:33.417812971Z 53 PC: 13412 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:33.419571117Z 53 PC: 13412 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:33.430182465Z 53 PC: 13412 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:33.431734587Z 53 PC: 13412 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:33.433282736Z 37 PC: 13427 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:33.435188672Z 37 PC: 1342f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:33.436852854Z 37 PC: 13437 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:33.438342174Z 37 PC: 1343f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:33.440450629Z 68 PC: 137b1 | I/O control for devices (Set for = '')
2018-12-17T22:38:33.533258654Z 37 PC: 12e35 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:33.571408951Z 37 PC: 13526 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:38:33.573487694Z 37 PC: 13526 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:38:33.577149693Z 37 PC: 13526 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:38:33.58514256Z 37 PC: 13526 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:38:33.590879589Z 37 PC: 13526 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:38:33.593633949Z 37 PC: 13526 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:33.59517434Z 37 PC: 13526 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:38:33.59666732Z 37 PC: 13526 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:38:33.609428613Z 37 PC: 13526 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:38:33.614697252Z 37 PC: 13526 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:38:33.616536093Z 37 PC: 13526 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:38:33.618774393Z 37 PC: 13526 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:38:33.624784526Z 37 PC: 13526 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:38:33.626550245Z 37 PC: 13526 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:38:33.628618653Z 37 PC: 13526 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:38:33.646694756Z 37 PC: 13526 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:38:33.648154547Z 37 PC: 13526 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:38:33.649804692Z 37 PC: 13526 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:38:33.651599172Z 37 PC: 13526 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:38:33.652994145Z 76 PC: 13565 | Terminate with return code (Return code = '0')