Sample viewer

vx.netlux.org/Trojan.DOS.Kilinst

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:57.630568932Z 53 PC: 139ba | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:57.631969733Z 53 PC: 139ba | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:57.634451253Z 53 PC: 139ba | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:57.636832225Z 53 PC: 139ba | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:57.640433168Z 53 PC: 139ba | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:57.649051475Z 53 PC: 139ba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:57.651450801Z 53 PC: 139ba | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:57.658225956Z 53 PC: 139ba | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:57.662111915Z 53 PC: 139ba | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:57.664944013Z 53 PC: 139ba | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:57.666628858Z 53 PC: 139ba | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:57.66841333Z 53 PC: 139ba | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:57.670899048Z 53 PC: 139ba | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:57.672655607Z 53 PC: 139ba | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:57.674475075Z 53 PC: 139ba | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:57.676853191Z 53 PC: 139ba | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:57.678547944Z 53 PC: 139ba | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:57.680350019Z 53 PC: 139ba | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:57.689855171Z 53 PC: 139ba | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:57.69166483Z 37 PC: 139cf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:57.693321481Z 37 PC: 139d7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:57.697757503Z 37 PC: 139df | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:57.699711934Z 37 PC: 139e7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:57.702630715Z 68 PC: 14365 | I/O control for devices (Set for = '�!2�R� ����]&')
2018-12-17T22:43:57.816902336Z 37 PC: 13221 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:57.819757008Z 61 PC: 14349 | Open file (Filename = 'instalar.exe')
2018-12-17T22:43:57.827641186Z 61 PC: 14349 | Open file (Filename = 'c:\keyb.exe')
2018-12-17T22:43:57.83468814Z 53 PC: 1392a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:57.836973784Z 37 PC: 13933 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:57.838508386Z 53 PC: 1392a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:57.840043599Z 37 PC: 13933 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:57.842678177Z 53 PC: 1392a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:57.844262713Z 37 PC: 13933 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:57.845788469Z 53 PC: 1392a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:57.849316285Z 37 PC: 13933 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:57.85089499Z 53 PC: 1392a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:57.852455871Z 37 PC: 13933 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:57.854810283Z 53 PC: 1392a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:57.856530103Z 37 PC: 13933 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:57.857802002Z 53 PC: 1392a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:57.859348316Z 37 PC: 13933 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:57.861278141Z 53 PC: 1392a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:57.86255559Z 37 PC: 13933 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:57.863919402Z 53 PC: 1392a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:57.875518426Z 37 PC: 13933 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:57.877153928Z 53 PC: 1392a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:57.880681904Z 37 PC: 13933 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:57.883773451Z 53 PC: 1392a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:57.885667208Z 37 PC: 13933 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:57.887912254Z 53 PC: 1392a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:57.890173411Z 37 PC: 13933 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:57.891898741Z 53 PC: 1392a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:57.893477596Z 37 PC: 13933 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:57.895825867Z 53 PC: 1392a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:57.897740503Z 37 PC: 13933 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:57.899266249Z 53 PC: 1392a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:57.901545109Z 37 PC: 13933 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:57.90815872Z 53 PC: 1392a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:57.910087332Z 37 PC: 13933 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:57.912161037Z 53 PC: 1392a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:57.916402273Z 37 PC: 13933 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:57.918743811Z 53 PC: 1392a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:57.920643729Z 37 PC: 13933 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:57.922997219Z 53 PC: 1392a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:57.92449904Z 37 PC: 13933 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:57.926835198Z 41 PC: 138e1 | Parse filename
2018-12-17T22:43:57.92974866Z 41 PC: 138ef | Parse filename
2018-12-17T22:43:57.932025486Z 75 PC: 138fa | Execute program
2018-12-17T22:43:57.954701134Z 80 PC: 182a9 | Set current PSP
2018-12-17T22:43:57.957024248Z 48 PC: 182ae | Get DOS version
2018-12-17T22:43:57.959684524Z 99 PC: 1ea90 | Get DBCS lead byte table pointer
2018-12-17T22:43:57.962987688Z 101 PC: 18334 | Get extended country info
2018-12-17T22:43:57.965614432Z 99 PC: 1833a | Get DBCS lead byte table pointer
2018-12-17T22:43:57.967894935Z 74 PC: 1839c | Reallocate memory
2018-12-17T22:43:57.969863662Z 25 PC: 183d3 | Get default drive
2018-12-17T22:43:57.971444892Z 37 PC: 17e93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:43:57.973602624Z 37 PC: 17e9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:57.975109905Z 37 PC: 17ea1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:57.979930329Z 74 PC: 1703c | Reallocate memory
2018-12-17T22:43:57.982446014Z 72 PC: 1707d | Allocate memory
2018-12-17T22:43:57.984882049Z 72 PC: 170b5 | Allocate memory
2018-12-17T22:43:57.987194763Z 72 PC: 170bd | Allocate memory