Sample viewer

vx.netlux.org/Trojan.DOS.Waster.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:24.461891172Z 48 PC: 1697c | Get DOS version
2018-12-17T22:43:24.463559893Z 74 PC: 169cc | Reallocate memory
2018-12-17T22:43:24.465879919Z 48 PC: 16a30 | Get DOS version
2018-12-17T22:43:24.468423651Z 53 PC: 16a38 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:24.4697937Z 37 PC: 16a4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:24.471285533Z 68 PC: 16adb | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T22:43:24.473879886Z 68 PC: 16adb | I/O control for devices
2018-12-17T22:43:24.475487523Z 68 PC: 16adb | I/O control for devices
2018-12-17T22:43:24.477016203Z 68 PC: 16adb | I/O control for devices
2018-12-17T22:43:24.478742548Z 68 PC: 16adb | I/O control for devices
2018-12-17T22:43:24.481876533Z 53 PC: 148fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:24.484293135Z 53 PC: 14907 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:24.48676971Z 53 PC: 14914 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:24.489054784Z 37 PC: 14929 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:24.499385711Z 37 PC: 14931 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:24.501086456Z 37 PC: 14939 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:24.507960495Z 53 PC: 153b8 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:43:24.509336346Z 53 PC: 153c5 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:43:24.51091782Z 53 PC: 153d4 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:43:24.513214154Z 37 PC: 153e1 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:43:24.514825971Z 53 PC: 153e8 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:43:24.51652584Z 37 PC: 153f5 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:43:24.518953039Z 53 PC: 15401 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:43:24.523854482Z 48 PC: 154c3 | Get DOS version
2018-12-17T22:43:24.525410059Z 68 PC: 14870 | I/O control for devices (Set for = '�����������������������������������������')
2018-12-17T22:43:24.534792883Z 68 PC: 14870 | I/O control for devices (Set for = '')
2018-12-17T22:43:24.548231352Z 51 PC: 1488e | Get or set Ctrl-Break
2018-12-17T22:43:24.549154992Z 51 PC: 1489a | Get or set Ctrl-Break
2018-12-17T22:43:24.550747914Z 72 PC: 12dc6 | Allocate memory
2018-12-17T22:43:24.55384517Z 37 PC: 13257 | Set interrupt vector (Interrupt = '9' AKA 'Display string')