Sample viewer

vx.netlux.org/Trojan.DOS.Aolphi

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:04.647955593Z 74 PC: 1311b | Reallocate memory
2018-12-17T22:45:04.650912056Z 48 PC: 13153 | Get DOS version
2018-12-17T22:45:04.653349393Z 74 PC: 15656 | Reallocate memory
2018-12-17T22:45:04.656935999Z 74 PC: 15656 | Reallocate memory
2018-12-17T22:45:04.66043459Z 74 PC: 15594 | Reallocate memory
2018-12-17T22:45:04.663889379Z 74 PC: 15656 | Reallocate memory
2018-12-17T22:45:04.667825Z 72 PC: 14fe4 | Allocate memory
2018-12-17T22:45:04.676277906Z 61 PC: 13337 | Open file (Filename = 'aolphi.bat')
2018-12-17T22:45:04.684358333Z 60 PC: 13409 | Create or truncate file
2018-12-17T22:45:04.702631793Z 68 PC: 13c17 | I/O control for devices (Set for = '')
2018-12-17T22:45:04.704871379Z 68 PC: 13c17 | I/O control for devices (Set for = '�ظ�/��s_Y���� ')
2018-12-17T22:45:04.70793837Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.711370095Z 68 PC: 13c17 | I/O control for devices (Set for = '')
2018-12-17T22:45:04.71371589Z 68 PC: 13c17 | I/O control for devices (Set for = '')
2018-12-17T22:45:04.719818222Z 66 PC: 14c12 | Move file pointer
2018-12-17T22:45:04.721836572Z 64 PC: 14c2c | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:45:04.734898544Z 66 PC: 14c12 | Move file pointer
2018-12-17T22:45:04.737921261Z 64 PC: 14c2c | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:45:04.747235595Z 66 PC: 14c12 | Move file pointer
2018-12-17T22:45:04.749109975Z 64 PC: 14c2c | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:45:04.758835081Z 66 PC: 14c12 | Move file pointer
2018-12-17T22:45:04.760912282Z 64 PC: 14c2c | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:45:04.769908679Z 66 PC: 14c12 | Move file pointer
2018-12-17T22:45:04.772818564Z 64 PC: 14c2c | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:45:04.782717035Z 66 PC: 14c12 | Move file pointer
2018-12-17T22:45:04.784829433Z 64 PC: 14c2c | Write file or device (Write 293 bytes on handle 5)
2018-12-17T22:45:04.790129086Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.793315791Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.795276333Z 62 PC: 13a9f | Close file
2018-12-17T22:45:04.805533658Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.809141374Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.813309482Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.815447708Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.820748664Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.822864298Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.82619887Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.834972909Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.837142163Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.838889104Z 66 PC: 13a6d | Move file pointer
2018-12-17T22:45:04.842397454Z 76 PC: 13270 | Terminate with return code (Return code = '0')