Sample viewer

vx.netlux.org/Trojan.DOS.Rompok

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:12.181052892Z 53 PC: 1376a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:12.183002229Z 53 PC: 1376a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:12.18466804Z 53 PC: 1376a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:12.185865156Z 53 PC: 1376a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:12.187973205Z 53 PC: 1376a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:12.189416042Z 53 PC: 1376a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:12.190805039Z 53 PC: 1376a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:12.192429365Z 53 PC: 1376a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:12.194388945Z 53 PC: 1376a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:12.195720117Z 53 PC: 1376a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:12.1969533Z 53 PC: 1376a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:12.204707321Z 53 PC: 1376a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:12.205911767Z 53 PC: 1376a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:12.207127297Z 53 PC: 1376a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:12.208986089Z 53 PC: 1376a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:12.21036419Z 53 PC: 1376a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:12.21230408Z 53 PC: 1376a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:12.214244463Z 53 PC: 1376a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:12.216490358Z 53 PC: 1376a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:12.217676548Z 37 PC: 1377f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:12.219019376Z 37 PC: 13787 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:12.220658705Z 37 PC: 1378f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:12.221943366Z 37 PC: 13797 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:12.223691785Z 68 PC: 1409a | I/O control for devices (Set for = '')
2018-12-17T21:57:12.338727611Z 64 PC: 13b88 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:57:12.340679279Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:12.342002872Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:57:12.343557127Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:57:12.344811388Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:57:12.346027429Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:12.347731196Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:12.348858035Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:57:12.349993508Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:57:12.35204585Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:57:12.35357648Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:57:12.355078933Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:57:12.357250436Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:57:12.358583115Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:57:12.359897484Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:57:12.361993998Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:57:12.36344019Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:57:12.364885138Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:57:12.366938386Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:57:12.368076722Z 37 PC: 138c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:57:12.373739556Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.37712596Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.379429269Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.381712929Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.3847031Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.386878608Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.389125275Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.391870034Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.393879306Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.395816725Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.398612021Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.400581272Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.402596422Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.40539184Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.407515357Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.409474213Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.412414811Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.414467572Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.416512145Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.419183189Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.421200821Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.423222532Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.42656301Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.429759853Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.432118261Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.435296295Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.437401462Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.439345623Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.442415641Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.444372457Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.446321043Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.448992337Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.450910429Z 6 PC: 13948 | Direct console I/O
2018-12-17T21:57:12.454512541Z 76 PC: 13900 | Terminate with return code (Return code = '200')