Sample viewer

vx.netlux.org/Trojan.DOS.QFat.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:25.75406489Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:45:25.755648584Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:25.76058729Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:45:25.762659131Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:45:25.764816894Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:45:25.76737107Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:25.770146874Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:45:25.773944326Z 26 PC: 13f55 | Set disk transfer address
2018-12-17T22:45:25.776852668Z 78 PC: 13f5f | Find first file
2018-12-17T22:45:25.784771411Z 65 PC: 1357e | Delete file (Filename = '\SLEEP.COM')
2018-12-17T22:45:25.804941333Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.809829494Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.815501446Z 65 PC: 1357e | Delete file (Filename = '\PRINT.S')
2018-12-17T22:45:25.830453508Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.834320732Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.839738297Z 65 PC: 1357e | Delete file (Filename = '\PRINT.COM')
2018-12-17T22:45:25.856022401Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.857484076Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.862492092Z 65 PC: 1357e | Delete file (Filename = '\HELLO.COM')
2018-12-17T22:45:25.877060413Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.878864571Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.884202076Z 65 PC: 1357e | Delete file (Filename = '\PHANG.COM')
2018-12-17T22:45:25.896721499Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.89840441Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.902758458Z 65 PC: 1357e | Delete file (Filename = '\PRINTA~1.COM')
2018-12-17T22:45:25.915648487Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.917281144Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.921316502Z 65 PC: 1357e | Delete file (Filename = '\MANDEL.COM')
2018-12-17T22:45:25.935011714Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.940394734Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.948141984Z 65 PC: 1357e | Delete file (Filename = '\PAH.COM')
2018-12-17T22:45:25.964561783Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.966160055Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.971274661Z 65 PC: 1357e | Delete file (Filename = '\TEST.EXE')
2018-12-17T22:45:25.987283127Z 26 PC: 13f77 | Set disk transfer address
2018-12-17T22:45:25.988675322Z 79 PC: 13f7b | Find next file
2018-12-17T22:45:25.99187424Z 26 PC: 13f55 | Set disk transfer address
2018-12-17T22:45:25.994577176Z 78 PC: 13f5f | Find first file
2018-12-17T22:45:26.005761683Z 26 PC: 13f55 | Set disk transfer address
2018-12-17T22:45:26.007015207Z 78 PC: 13f5f | Find first file
2018-12-17T22:45:26.015512526Z 37 PC: 12bef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:26.017379913Z 37 PC: 12bfa | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:45:26.018973306Z 37 PC: 12c05 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:45:26.020961631Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:45:26.023870875Z 64 PC: 12c21 | Write file or device (Write 25 bytes on handle 2)
2018-12-17T22:45:26.028673524Z 76 PC: 12b98 | Terminate with return code (Return code = '255')