Sample viewer

vx.netlux.org/Trojan.DOS.NeedHelp

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:04.197992101Z 53 PC: 130fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:04.199463038Z 53 PC: 130fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:04.200476469Z 53 PC: 130fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:04.201448994Z 53 PC: 130fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:04.202797069Z 53 PC: 130fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:04.204103402Z 53 PC: 130fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:04.205084963Z 53 PC: 130fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:04.20613043Z 53 PC: 130fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:04.207176371Z 53 PC: 130fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:04.208117471Z 53 PC: 130fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:04.208989739Z 53 PC: 130fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:04.210229878Z 53 PC: 130fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:04.21123159Z 53 PC: 130fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:04.212270121Z 53 PC: 130fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:04.21399896Z 53 PC: 130fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:04.215025151Z 53 PC: 130fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:04.2159626Z 53 PC: 130fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:04.217650445Z 53 PC: 130fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:04.219006775Z 53 PC: 130fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:04.220225806Z 37 PC: 1310f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:04.221871161Z 37 PC: 13117 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:04.222807852Z 37 PC: 1311f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:04.223767026Z 37 PC: 13127 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:04.22562046Z 68 PC: 13527 | I/O control for devices (Set for = ',0����Æ������&k2�:�s���듎�� �uÎ��ؿ ')
2018-12-17T21:51:04.226909902Z 53 PC: 13078 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:04.227980126Z 37 PC: 13081 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:51:04.229429925Z 53 PC: 13078 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:04.230573697Z 37 PC: 13081 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:51:04.231500468Z 53 PC: 13078 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:04.233021578Z 37 PC: 13081 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:51:04.233979818Z 53 PC: 13078 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:04.235054009Z 37 PC: 13081 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:04.236779771Z 53 PC: 13078 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:04.238027239Z 37 PC: 13081 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:04.239719498Z 53 PC: 13078 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:04.24167757Z 37 PC: 13081 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:04.243622723Z 53 PC: 13078 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:04.245487223Z 37 PC: 13081 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:51:04.246573964Z 53 PC: 13078 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:04.247587774Z 37 PC: 13081 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:51:04.248763498Z 53 PC: 13078 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:04.25015879Z 37 PC: 13081 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:51:04.251184706Z 53 PC: 13078 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:04.252153639Z 37 PC: 13081 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:51:04.256651042Z 53 PC: 13078 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:04.257806695Z 37 PC: 13081 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:51:04.258733209Z 53 PC: 13078 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:04.26024465Z 37 PC: 13081 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:51:04.261195394Z 53 PC: 13078 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:04.262202739Z 37 PC: 13081 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:51:04.264051096Z 53 PC: 13078 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:04.265170718Z 37 PC: 13081 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:51:04.266576919Z 53 PC: 13078 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:04.268401761Z 37 PC: 13081 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:51:04.269485131Z 53 PC: 13078 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:04.270528Z 37 PC: 13081 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:51:04.272196151Z 53 PC: 13078 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:04.273715823Z 37 PC: 13081 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:51:04.274668351Z 53 PC: 13078 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:04.276596825Z 37 PC: 13081 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:51:04.278023815Z 53 PC: 13078 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:04.279369678Z 37 PC: 13081 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:51:04.281753442Z 41 PC: 1302f | Parse filename
2018-12-17T21:51:04.28339666Z 41 PC: 1303d | Parse filename
2018-12-17T21:51:04.285067897Z 75 PC: 13048 | Execute program
2018-12-17T21:51:04.307013174Z 80 PC: 170e9 | Set current PSP
2018-12-17T21:51:04.308120969Z 48 PC: 170ee | Get DOS version
2018-12-17T21:51:04.309838635Z 99 PC: 1d8d0 | Get DBCS lead byte table pointer
2018-12-17T21:51:04.313509895Z 101 PC: 17174 | Get extended country info
2018-12-17T21:51:04.315653218Z 99 PC: 1717a | Get DBCS lead byte table pointer
2018-12-17T21:51:04.317384512Z 74 PC: 171dc | Reallocate memory
2018-12-17T21:51:04.319226644Z 25 PC: 17213 | Get default drive
2018-12-17T21:51:04.320254891Z 37 PC: 16cd3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:51:04.321322086Z 37 PC: 16cda | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:04.322815827Z 37 PC: 16ce1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:04.327155027Z 74 PC: 15e7c | Reallocate memory
2018-12-17T21:51:04.328539495Z 72 PC: 15ebd | Allocate memory
2018-12-17T21:51:04.330766556Z 72 PC: 15ef5 | Allocate memory
2018-12-17T21:51:04.332491013Z 72 PC: 15efd | Allocate memory