Sample viewer

vx.netlux.org/Trojan.DOS.Viewer

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:02.078513053Z 48 PC: 1682c | Get DOS version
2018-12-17T22:40:02.080565046Z 74 PC: 1687c | Reallocate memory
2018-12-17T22:40:02.08322308Z 48 PC: 168e0 | Get DOS version
2018-12-17T22:40:02.085146602Z 53 PC: 168e8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:02.088099938Z 37 PC: 168fa | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:02.089671951Z 53 PC: 18f82 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:02.091023448Z 37 PC: 18f92 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:02.092232129Z 53 PC: 18f97 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:02.094222965Z 37 PC: 18fa7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:02.095371648Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:02.096874228Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:02.098554323Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:02.099956461Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:02.10130228Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:02.102995835Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:02.104384568Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:02.105492702Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:02.107556348Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:02.109343479Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:02.111088611Z 53 PC: 16cd6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:40:02.113791389Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:02.115046527Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:02.116108739Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:02.117789987Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:02.119024736Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:02.120190767Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:02.122173489Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:02.123086355Z 37 PC: 16d05 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:02.123935232Z 37 PC: 16d0c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:02.125727201Z 37 PC: 16d11 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:02.127022372Z 68 PC: 1698b | I/O control for devices (Set for = '��|�')
2018-12-17T22:40:02.128421744Z 68 PC: 1698b | I/O control for devices
2018-12-17T22:40:02.129621584Z 68 PC: 1698b | I/O control for devices (Set for = ' "$&(*,.02468:<>@BDFHJLNPRTVXZ\^`bdfhjlnprtvxz|~����������������������������������������������������������������')
2018-12-17T22:40:02.131533161Z 68 PC: 1698b | I/O control for devices (Set for = '468:<>@BDFHJLNPRTVXZ\^`bdfhjlnprtvxz|~����������������������������������������������������������������')
2018-12-17T22:40:02.132675394Z 68 PC: 1698b | I/O control for devices (Set for = '468:<>@BDFHJLNPRTVXZ\^`bdfhjlnprtvxz|~����������������������������������������������������������������')
2018-12-17T22:40:02.1340209Z 53 PC: 14b2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:02.147373073Z 53 PC: 14b37 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:40:02.148724127Z 53 PC: 14b44 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:02.150392285Z 37 PC: 14b59 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:02.152646176Z 37 PC: 14b61 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:40:02.153869763Z 37 PC: 14b69 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:02.155489341Z 53 PC: 155e8 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:40:02.157332755Z 53 PC: 155f5 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:40:02.158900376Z 53 PC: 15604 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:40:02.160286802Z 37 PC: 15611 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:40:02.162160668Z 53 PC: 15618 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:40:02.163554195Z 37 PC: 15625 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:40:02.16485264Z 53 PC: 15631 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:40:02.169748745Z 48 PC: 156f3 | Get DOS version
2018-12-17T22:40:02.171581859Z 74 PC: 13585 | Reallocate memory
2018-12-17T22:40:02.173965651Z 74 PC: 13585 | Reallocate memory
2018-12-17T22:40:02.175681529Z 68 PC: 14aa0 | I/O control for devices (Set for = 'LA PHOTO(RECOMMENDER)�1')
2018-12-17T22:40:02.177911336Z 68 PC: 14aa0 | I/O control for devices (Set for = '')
2018-12-17T22:40:02.179916996Z 51 PC: 14abe | Get or set Ctrl-Break
2018-12-17T22:40:02.180827932Z 51 PC: 14aca | Get or set Ctrl-Break
2018-12-17T22:40:02.182990331Z 72 PC: 12c60 | Allocate memory
2018-12-17T22:40:02.18532559Z 74 PC: 13585 | Reallocate memory
2018-12-17T22:40:02.187047328Z 72 PC: 12c60 | Allocate memory
2018-12-17T22:40:02.197091551Z 73 PC: 12c60 | Release memory
2018-12-17T22:40:02.1995665Z 74 PC: 13585 | Reallocate memory
2018-12-17T22:40:02.201130639Z 51 PC: 14ad5 | Get or set Ctrl-Break
2018-12-17T22:40:02.202827236Z 53 PC: 12fb2 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:40:02.204061626Z 53 PC: 12fbf | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:40:02.205224978Z 53 PC: 12fcc | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:40:02.211958591Z 37 PC: 12fe7 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:40:02.213381678Z 53 PC: 12fef | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:40:02.21487605Z 37 PC: 12ffc | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:40:02.217032107Z 53 PC: 13003 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:40:02.218867692Z 37 PC: 13010 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:40:02.220654555Z 37 PC: 1301a | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:40:02.223340374Z 37 PC: 13025 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:40:02.226526327Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:40:02.227694619Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:40:02.22962325Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:40:02.231153643Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:40:02.232410607Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:40:02.233876314Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:40:02.236115989Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:40:02.23788137Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:40:02.239869538Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:40:02.241779461Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:40:02.242984453Z 37 PC: 16d21 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:40:02.244188246Z 37 PC: 18fb6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:40:02.24606707Z 37 PC: 16a3c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:40:02.248720455Z 41 PC: 1661d | Parse filename
2018-12-17T22:40:02.250431712Z 41 PC: 1661f | Parse filename
2018-12-17T22:40:02.252895008Z 41 PC: 16624 | Parse filename
2018-12-17T22:40:02.254605248Z 75 PC: 1663a | Execute program
2018-12-17T22:40:02.279807569Z 80 PC: 1c1f9 | Set current PSP
2018-12-17T22:40:02.282301438Z 48 PC: 1c1fe | Get DOS version
2018-12-17T22:40:02.284595374Z 99 PC: 229e0 | Get DBCS lead byte table pointer
2018-12-17T22:40:02.288683955Z 101 PC: 1c284 | Get extended country info
2018-12-17T22:40:02.29116715Z 99 PC: 1c28a | Get DBCS lead byte table pointer
2018-12-17T22:40:02.294081915Z 74 PC: 1c2ec | Reallocate memory
2018-12-17T22:40:02.298402375Z 25 PC: 1c323 | Get default drive
2018-12-17T22:40:02.30161989Z 37 PC: 1bde3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:40:02.303511802Z 37 PC: 1bdea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:02.305393265Z 37 PC: 1bdf1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:02.31138481Z 74 PC: 1af8c | Reallocate memory
2018-12-17T22:40:02.313423376Z 72 PC: 1afcd | Allocate memory
2018-12-17T22:40:02.31567315Z 72 PC: 1b005 | Allocate memory
2018-12-17T22:40:02.31852704Z 72 PC: 1b00d | Allocate memory