Sample viewer

vx.netlux.org/Trojan.DOS.FormatC.l

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:05.620668492Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:05.622485014Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:05.623841027Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:05.625067508Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:05.626694226Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:05.628262328Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:05.62970097Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:05.631855918Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:05.633511104Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:05.634882227Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:05.637871507Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:05.63896891Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:05.639993951Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:05.641439072Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:05.642488613Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:05.643763901Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:05.645374123Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:05.646674604Z 53 PC: 133b6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:05.647786679Z 37 PC: 133cb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:05.649015582Z 37 PC: 133d3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:05.650775729Z 37 PC: 133db | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:05.651840929Z 37 PC: 133e3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:05.653395166Z 68 PC: 1392f | I/O control for devices (Set for = '')
2018-12-17T22:41:05.750110493Z 37 PC: 12de7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:05.7542657Z 60 PC: 13916 | Create or truncate file
2018-12-17T22:41:06.100528837Z 68 PC: 1392f | I/O control for devices (Set for = 'c:\autoexec.bat')
2018-12-17T22:41:06.10508263Z 64 PC: 13a0d | Write file or device (Write 27 bytes on handle 5)
2018-12-17T22:41:06.118477673Z 62 PC: 13a4c | Close file
2018-12-17T22:41:06.129418806Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:06.133586876Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:06.136096273Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:06.138069834Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:06.149159731Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:06.151591875Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:06.153127701Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:06.155825531Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:06.15726085Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:06.158701595Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:06.170944577Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:06.172231936Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:06.173402712Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:06.175103525Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:06.176176514Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:06.177510962Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:06.180308294Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:06.182296356Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:06.183772178Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:06.186304912Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:06.187757735Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:06.189293338Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:06.19199028Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:06.193731615Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:06.195326277Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:06.196628074Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:06.198344986Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:06.199320296Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:06.200495318Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:06.202175326Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:06.203646198Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:06.205396264Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:06.207767695Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:06.209184132Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:06.210576415Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:06.21411346Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:06.216063902Z 41 PC: 12ca9 | Parse filename
2018-12-17T22:41:06.217804882Z 41 PC: 12cb7 | Parse filename
2018-12-17T22:41:06.220663342Z 75 PC: 12cc2 | Execute program
2018-12-17T22:41:06.243602116Z 80 PC: 17819 | Set current PSP
2018-12-17T22:41:06.24465614Z 48 PC: 1781e | Get DOS version
2018-12-17T22:41:06.247153335Z 99 PC: 1e000 | Get DBCS lead byte table pointer
2018-12-17T22:41:06.250196997Z 101 PC: 178a4 | Get extended country info
2018-12-17T22:41:06.25173101Z 99 PC: 178aa | Get DBCS lead byte table pointer
2018-12-17T22:41:06.254036333Z 74 PC: 1790c | Reallocate memory
2018-12-17T22:41:06.25580741Z 25 PC: 17943 | Get default drive
2018-12-17T22:41:06.257269703Z 37 PC: 17403 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:41:06.259899971Z 37 PC: 1740a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:06.261495712Z 37 PC: 17411 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:06.265896851Z 74 PC: 165ac | Reallocate memory
2018-12-17T22:41:06.267852315Z 72 PC: 165ed | Allocate memory
2018-12-17T22:41:06.269084024Z 72 PC: 16625 | Allocate memory
2018-12-17T22:41:06.271308665Z 72 PC: 1662d | Allocate memory