Sample viewer

vx.netlux.org/Trojan.DOS.Loader.SAD.6288

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:37.297813091Z 53 PC: 138aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:37.29922081Z 53 PC: 138aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:37.301386744Z 53 PC: 138aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:37.303107442Z 53 PC: 138aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:37.304796981Z 53 PC: 138aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:37.307379161Z 53 PC: 138aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:37.30906705Z 53 PC: 138aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:37.310774115Z 53 PC: 138aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:37.313526655Z 53 PC: 138aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:37.315228465Z 53 PC: 138aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:37.316929723Z 53 PC: 138aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:37.329850847Z 53 PC: 138aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:37.331894729Z 53 PC: 138aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:37.333742943Z 53 PC: 138aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:37.335688914Z 53 PC: 138aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:37.339047396Z 53 PC: 138aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:37.341656525Z 53 PC: 138aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:37.344125066Z 53 PC: 138aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:37.346107613Z 53 PC: 138aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:37.348475069Z 37 PC: 138bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:37.350143938Z 37 PC: 138c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:37.351762019Z 37 PC: 138cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:37.355277984Z 37 PC: 138d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:37.357454489Z 68 PC: 13fc6 | I/O control for devices (Set for = '������������^ÿ��3��a=��t=')
2018-12-17T22:41:37.475238248Z 64 PC: 13cc8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:41:37.478109166Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:37.479669701Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:37.481166488Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:41:37.482927048Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:37.484748022Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:37.486244096Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:37.487717926Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:37.490340002Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:37.492391293Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:37.494469725Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:37.497555572Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:37.499195461Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:37.500783396Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:37.50307194Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:37.504592308Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:37.506096467Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:37.508613192Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:37.510107088Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:41:37.51153649Z 37 PC: 13a01 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:37.513516296Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.515899175Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.519150913Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.521667596Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.524238707Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.534733625Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.53746164Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.540414269Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.543192919Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.546176391Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.550449989Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.553017512Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.555561902Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.559519857Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.562298323Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.566204307Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.570884424Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.573677119Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.57659137Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.579995002Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.582892107Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.585666156Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.588551559Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.591526314Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.594247282Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.597144158Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.600660987Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.603012914Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.605471013Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.608564923Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.611135221Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.613736674Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.617213473Z 6 PC: 13a88 | Direct console I/O
2018-12-17T22:41:37.621603889Z 76 PC: 13a40 | Terminate with return code (Return code = '200')