Sample viewer

vx.netlux.org/Trojan.DOS.Deltree32

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:14.157058528Z 48 PC: 12aa3 | Get DOS version
2018-12-17T22:42:14.187148042Z 74 PC: 12acb | Reallocate memory
2018-12-17T22:42:14.189811938Z 88 PC: 12f18 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.191811481Z 88 PC: 12f20 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.195180459Z 88 PC: 12f2b | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.19756789Z 88 PC: 12f33 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.199788332Z 75 PC: 12efd | Execute program
2018-12-17T22:42:14.208323092Z 88 PC: 12f49 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.210066401Z 88 PC: 12f54 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.211723497Z 88 PC: 12f18 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.213722161Z 88 PC: 12f20 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.215026982Z 88 PC: 12f2b | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.216196312Z 88 PC: 12f33 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.218549255Z 75 PC: 12efd | Execute program
2018-12-17T22:42:14.232533502Z 88 PC: 12f49 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.234658638Z 88 PC: 12f54 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.236705194Z 88 PC: 12f18 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.239462801Z 88 PC: 12f20 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.241285733Z 88 PC: 12f2b | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.243078064Z 88 PC: 12f33 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.246251284Z 75 PC: 12efd | Execute program
2018-12-17T22:42:14.252008315Z 88 PC: 12f49 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.25398421Z 88 PC: 12f54 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.258439325Z 88 PC: 12f18 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.260168253Z 88 PC: 12f20 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.261930645Z 88 PC: 12f2b | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.264348501Z 88 PC: 12f33 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.266208267Z 75 PC: 12efd | Execute program
2018-12-17T22:42:14.271700825Z 88 PC: 12f49 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.273588537Z 88 PC: 12f54 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.282631288Z 88 PC: 12f18 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.28403969Z 88 PC: 12f20 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.285375872Z 88 PC: 12f2b | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.289097025Z 88 PC: 12f33 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.291468713Z 75 PC: 12efd | Execute program
2018-12-17T22:42:14.299379257Z 88 PC: 12f49 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.302731516Z 88 PC: 12f54 | case 0xGet or set allocation strateg:
2018-12-17T22:42:14.304531178Z 2 PC: 12e79 | Character output (Char = '4c')
2018-12-17T22:42:14.307225889Z 2 PC: 12e79 | Character output (Char = '6f')
2018-12-17T22:42:14.31081789Z 2 PC: 12e79 | Character output (Char = '61')
2018-12-17T22:42:14.313748981Z 2 PC: 12e79 | Character output (Char = '64')
2018-12-17T22:42:14.316667208Z 2 PC: 12e79 | Character output (Char = '20')
2018-12-17T22:42:14.320018749Z 2 PC: 12e79 | Character output (Char = '65')
2018-12-17T22:42:14.323089048Z 2 PC: 12e79 | Character output (Char = '72')
2018-12-17T22:42:14.32568597Z 2 PC: 12e79 | Character output (Char = '72')
2018-12-17T22:42:14.328824932Z 2 PC: 12e79 | Character output (Char = '6f')
2018-12-17T22:42:14.331286892Z 2 PC: 12e79 | Character output (Char = '72')
2018-12-17T22:42:14.333632021Z 2 PC: 12e79 | Character output (Char = '3a')
2018-12-17T22:42:14.336538684Z 2 PC: 12e79 | Character output (Char = '20')
2018-12-17T22:42:14.339629543Z 2 PC: 12e79 | Character output (Char = '6e')
2018-12-17T22:42:14.342518692Z 2 PC: 12e79 | Character output (Char = '6f')
2018-12-17T22:42:14.345883224Z 2 PC: 12e79 | Character output (Char = '20')
2018-12-17T22:42:14.348972632Z 2 PC: 12e79 | Character output (Char = '44')
2018-12-17T22:42:14.35294092Z 2 PC: 12e79 | Character output (Char = '50')
2018-12-17T22:42:14.356072955Z 2 PC: 12e79 | Character output (Char = '4d')
2018-12-17T22:42:14.359649451Z 2 PC: 12e79 | Character output (Char = '49')
2018-12-17T22:42:14.362563035Z 2 PC: 12e79 | Character output (Char = '20')
2018-12-17T22:42:14.365336383Z 2 PC: 12e79 | Character output (Char = '2d')
2018-12-17T22:42:14.369048447Z 2 PC: 12e79 | Character output (Char = '20')
2018-12-17T22:42:14.371940412Z 2 PC: 12e79 | Character output (Char = '47')
2018-12-17T22:42:14.374644699Z 2 PC: 12e79 | Character output (Char = '65')
2018-12-17T22:42:14.378242136Z 2 PC: 12e79 | Character output (Char = '74')
2018-12-17T22:42:14.380886393Z 2 PC: 12e79 | Character output (Char = '20')
2018-12-17T22:42:14.383547315Z 2 PC: 12e79 | Character output (Char = '63')
2018-12-17T22:42:14.386757148Z 2 PC: 12e79 | Character output (Char = '73')
2018-12-17T22:42:14.389270115Z 2 PC: 12e79 | Character output (Char = '64')
2018-12-17T22:42:14.391845918Z 2 PC: 12e79 | Character output (Char = '70')
2018-12-17T22:42:14.395270545Z 2 PC: 12e79 | Character output (Char = '6d')
2018-12-17T22:42:14.397996621Z 2 PC: 12e79 | Character output (Char = '69')
2018-12-17T22:42:14.400599778Z 2 PC: 12e79 | Character output (Char = '2a')
2018-12-17T22:42:14.404064996Z 2 PC: 12e79 | Character output (Char = '62')
2018-12-17T22:42:14.406768179Z 2 PC: 12e79 | Character output (Char = '2e')
2018-12-17T22:42:14.409625138Z 2 PC: 12e79 | Character output (Char = '7a')
2018-12-17T22:42:14.412683457Z 2 PC: 12e79 | Character output (Char = '69')
2018-12-17T22:42:14.415574002Z 2 PC: 12e79 | Character output (Char = '70')
2018-12-17T22:42:14.418284845Z 2 PC: 12e79 | Character output (Char = '0d')
2018-12-17T22:42:14.421041656Z 2 PC: 12e79 | Character output (Char = '0a')
2018-12-17T22:42:14.42567512Z 76 PC: 12e74 | Terminate with return code (Return code = '255')