Sample viewer

vx.netlux.org/Trojan.DOS.AidsInfo.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:27.424183019Z 48 PC: 34c96 | Get DOS version
2018-12-17T22:42:27.427462408Z 74 PC: 25f46 | Reallocate memory
2018-12-17T22:42:27.429614741Z 72 PC: 21986 | Allocate memory
2018-12-17T22:42:27.43283519Z 48 PC: 219f0 | Get DOS version
2018-12-17T22:42:27.434428542Z 68 PC: 21c6d | I/O control for devices (Set for = '')
2018-12-17T22:42:27.436052071Z 68 PC: 21c6d | I/O control for devices (Set for = 'tional means can beG')
2018-12-17T22:42:27.438348855Z 51 PC: 244df | Get or set Ctrl-Break
2018-12-17T22:42:27.439430727Z 51 PC: 244eb | Get or set Ctrl-Break
2018-12-17T22:42:27.440746879Z 53 PC: 244f6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:27.44602369Z 53 PC: 24503 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:42:27.448370408Z 53 PC: 24510 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:27.450769503Z 37 PC: 24526 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:27.454137789Z 37 PC: 2452e | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:42:27.456764193Z 37 PC: 24536 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:27.45903627Z 53 PC: 248b5 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:27.462100645Z 53 PC: 248c2 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:27.466247183Z 53 PC: 248d1 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:27.467533209Z 37 PC: 248de | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:27.470045267Z 53 PC: 248e5 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:27.471705265Z 37 PC: 248f2 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:27.473269262Z 53 PC: 248fe | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:42:27.482945857Z 48 PC: 249ed | Get DOS version
2018-12-17T22:42:27.489087622Z 61 PC: 2838e | Open file (Filename = 'C:\ \ \ \_. _')
2018-12-17T22:42:27.500847719Z 37 PC: 24be4 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:42:27.503065785Z 53 PC: 24beb | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:27.504499689Z 37 PC: 24bf8 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:27.506247962Z 37 PC: 24c03 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:42:27.507674662Z 37 PC: 24c0e | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:42:27.508959034Z 37 PC: 247e8 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:42:27.511252642Z 37 PC: 247f2 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:42:27.512609731Z 37 PC: 247fc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:27.514093858Z 51 PC: 24808 | Get or set Ctrl-Break
2018-12-17T22:42:27.515901764Z 76 PC: 21a63 | Terminate with return code (Return code = '0')