Sample viewer

vx.netlux.org/Trojan.DOS.EatFlu.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:28.025681716Z 48 PC: 12a4b | Get DOS version
2018-12-17T22:45:28.027335598Z 53 PC: 12b83 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:28.028440839Z 53 PC: 12b90 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:45:28.029530854Z 53 PC: 12b9d | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:45:28.031647954Z 53 PC: 12baa | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:45:28.032724834Z 37 PC: 12bbe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:28.033911899Z 74 PC: 12af3 | Reallocate memory
2018-12-17T22:45:28.036768748Z 68 PC: 138da | I/O control for devices (Set for = '��')
2018-12-17T22:45:28.038562939Z 68 PC: 138da | I/O control for devices (Set for = '� ��')
2018-12-17T22:45:28.040548324Z 59 PC: 137b5 | Change current directory
2018-12-17T22:45:28.044523471Z 255 PC: 12c98 | UNKNOWN!
2018-12-17T22:45:28.045653512Z 42 PC: 130a3 | Get date 0x130a3: mov word ptr [si], cx
0x130a5: mov word ptr [si + 2], dx
0x130a8: pop si
0x130a9: pop bp
0x130aa: ret
0x130ab: push bp
0x130ac: mov bp, sp
0x130ae: push si
0x130af: mov si, word ptr [bp + 4]
0x130b2: mov ah, 0x2c
0x130b4: int 0x21
0x130b6: mov word ptr [si], cx
0x130b8: mov word ptr [si + 2], dx
0x130bb: pop si
0x130bc: pop bp
0x130bd: ret
0x130be: push bp
0x130bf: mov bp, sp
0x130c1: mov ax, word ptr [bp + 4]
0x130c4: mov word ptr [0x1aee], 0
2018-12-17T22:45:28.047667689Z 44 PC: 130b6 | Get time 0x130b6: mov word ptr [si], cx
0x130b8: mov word ptr [si + 2], dx
0x130bb: pop si
0x130bc: pop bp
0x130bd: ret
0x130be: push bp
0x130bf: mov bp, sp
0x130c1: mov ax, word ptr [bp + 4]
0x130c4: mov word ptr [0x1aee], 0
0x130ca: mov word ptr [0x1aec], ax
0x130cd: pop bp
0x130ce: ret
0x130cf: mov cx, word ptr [0x1aee]
0x130d3: mov bx, word ptr [0x1aec]
0x130d7: mov dx, 0x15a
0x130da: mov ax, 0x4e35
0x130dd: call 0x13f95
0x130e0: add ax, 1
0x130e3: adc dx, 0
0x130e6: mov word ptr [0x1aee], dx
2018-12-17T22:45:28.050851938Z 47 PC: 137dc | Get disk transfer address
2018-12-17T22:45:28.052354667Z 26 PC: 137e5 | Set disk transfer address
2018-12-17T22:45:28.053261941Z 78 PC: 137ef | Find first file
2018-12-17T22:45:28.059020519Z 26 PC: 137f8 | Set disk transfer address
2018-12-17T22:45:28.06311998Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.069136787Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.070080966Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.071548759Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.073969422Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.075098285Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.229486974Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.230608309Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.231663003Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.234925022Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.236409691Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.247390213Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.25789891Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.259133114Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.26178343Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.263866222Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.27065636Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.271783184Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.272850227Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.276134922Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.277368762Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.290908296Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.293142611Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.294589798Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.29750191Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.300465276Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.311969491Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.313453209Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.315810249Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.31895708Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.320488728Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.332312876Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.33406588Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.335418771Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.338421132Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.341180627Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.352198475Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.353583117Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.355950709Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.358779184Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.360279414Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.375389831Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.376740946Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.378056255Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.381434507Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.382989885Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.388922504Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.391073997Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.392408531Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.395069043Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.397746599Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.402563885Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.403872308Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.405815651Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.408444025Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.409897291Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.424503678Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.426324235Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.427690338Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.431478194Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.432838391Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.446645189Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.448596863Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.449676563Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.452166527Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.454177988Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.465923457Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.467250754Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.468541839Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.472372779Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.474283164Z 86 PC: 12ddd | Rename file
2018-12-17T22:45:28.485382672Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.487839978Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.489153169Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.491698435Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.494195831Z 47 PC: 137dc | Get disk transfer address
2018-12-17T22:45:28.495479439Z 26 PC: 137e5 | Set disk transfer address
2018-12-17T22:45:28.496691509Z 78 PC: 137ef | Find first file
2018-12-17T22:45:28.50847126Z 26 PC: 137f8 | Set disk transfer address
2018-12-17T22:45:28.509831184Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.511248556Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.512989619Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.515734371Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.516915378Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.518815962Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.521278611Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.523942982Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.525939634Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.527609093Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.528912134Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.532320567Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.534110684Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.535435899Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.537354692Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.540414359Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.541508946Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.542762839Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.544253996Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.546805342Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.548362357Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.550453935Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.551702673Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.554331488Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.556650377Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.557971573Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.559225848Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.562841672Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.564188184Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.565483863Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.567689577Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.570484061Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.571615513Z 47 PC: 1380f | Get disk transfer address
2018-12-17T22:45:28.573499438Z 26 PC: 13818 | Set disk transfer address
2018-12-17T22:45:28.574612282Z 79 PC: 1381c | Find next file
2018-12-17T22:45:28.576827696Z 26 PC: 13825 | Set disk transfer address
2018-12-17T22:45:28.579610491Z 37 PC: 12bca | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:28.580725424Z 37 PC: 12bd5 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:45:28.581833461Z 37 PC: 12be0 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:45:28.583743997Z 37 PC: 12beb | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:45:28.585196616Z 76 PC: 12b74 | Terminate with return code (Return code = '0')