Sample viewer

vx.netlux.org/Trojan.DOS.DirtyGuy

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:17.383643331Z 53 PC: 1320a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:17.385119933Z 53 PC: 1320a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:17.386078004Z 53 PC: 1320a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:17.386994033Z 53 PC: 1320a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:17.388499464Z 53 PC: 1320a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:17.389440692Z 53 PC: 1320a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:17.390547475Z 53 PC: 1320a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:17.392041479Z 53 PC: 1320a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:17.393081057Z 53 PC: 1320a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:17.394057951Z 53 PC: 1320a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:17.395476514Z 53 PC: 1320a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:17.396425019Z 53 PC: 1320a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:17.397188082Z 53 PC: 1320a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:17.401740956Z 53 PC: 1320a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:17.40258389Z 53 PC: 1320a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:17.403359052Z 53 PC: 1320a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:17.404494784Z 53 PC: 1320a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:17.405758205Z 53 PC: 1320a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:17.406648309Z 53 PC: 1320a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:17.407606425Z 37 PC: 1321f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:17.408632381Z 37 PC: 13227 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:17.409420285Z 37 PC: 1322f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:17.410199192Z 37 PC: 13237 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:17.411832308Z 68 PC: 13895 | I/O control for devices (Set for = '�<%uۋ� �u���')
2018-12-17T22:43:17.476512251Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')