Sample viewer

vx.netlux.org/Trojan.DOS.FormatC.q

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:27.837952458Z 53 PC: 135aa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:27.839649265Z 53 PC: 135aa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:27.854948748Z 53 PC: 135aa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:27.857397461Z 53 PC: 135aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:27.859867058Z 53 PC: 135aa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:27.862097956Z 53 PC: 135aa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:27.863547445Z 53 PC: 135aa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:27.865423897Z 53 PC: 135aa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:27.869378968Z 53 PC: 135aa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:27.870901602Z 53 PC: 135aa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:27.872535156Z 53 PC: 135aa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:27.874890675Z 53 PC: 135aa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:27.876431823Z 53 PC: 135aa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:27.878035355Z 53 PC: 135aa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:27.890136141Z 53 PC: 135aa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:27.891853423Z 53 PC: 135aa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:27.893484252Z 53 PC: 135aa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:27.895181164Z 53 PC: 135aa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:27.897552621Z 53 PC: 135aa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:27.899339177Z 37 PC: 135bf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:27.901102845Z 37 PC: 135c7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:27.911451469Z 37 PC: 135cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:27.913127686Z 37 PC: 135d7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:27.915410396Z 68 PC: 13e51 | I/O control for devices (Set for = '~')
2018-12-17T22:46:28.01439533Z 37 PC: 12e91 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:28.019699087Z 53 PC: 13528 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:28.021523316Z 37 PC: 13531 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:28.023801767Z 53 PC: 13528 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:28.026393879Z 37 PC: 13531 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:28.029531919Z 53 PC: 13528 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:28.040951162Z 37 PC: 13531 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:28.043387897Z 53 PC: 13528 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:28.044747516Z 37 PC: 13531 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:28.046063308Z 53 PC: 13528 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:28.047874601Z 37 PC: 13531 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:28.049491378Z 53 PC: 13528 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:28.050872288Z 37 PC: 13531 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:28.052544191Z 53 PC: 13528 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:28.054095795Z 37 PC: 13531 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:28.055240259Z 53 PC: 13528 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:28.056408196Z 37 PC: 13531 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:28.057883077Z 53 PC: 13528 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:28.070499253Z 37 PC: 13531 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:28.072115786Z 53 PC: 13528 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:28.074535708Z 37 PC: 13531 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:28.075840071Z 53 PC: 13528 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:28.077103562Z 37 PC: 13531 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:28.079050743Z 53 PC: 13528 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:28.081174064Z 37 PC: 13531 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:28.082570413Z 53 PC: 13528 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:28.084719963Z 37 PC: 13531 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:28.086193151Z 53 PC: 13528 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:28.087643696Z 37 PC: 13531 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:28.09047475Z 53 PC: 13528 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:28.09210635Z 37 PC: 13531 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:28.093687231Z 53 PC: 13528 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:28.097071419Z 37 PC: 13531 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:28.098658149Z 53 PC: 13528 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:28.100218655Z 37 PC: 13531 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:28.101915907Z 53 PC: 13528 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:28.110599572Z 37 PC: 13531 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:28.112024489Z 53 PC: 13528 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:28.113630187Z 37 PC: 13531 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:28.117914586Z 41 PC: 134df | Parse filename
2018-12-17T22:46:28.12111915Z 41 PC: 134ed | Parse filename
2018-12-17T22:46:28.125480971Z 75 PC: 134f8 | Execute program
2018-12-17T22:46:28.159552707Z 80 PC: 17bd9 | Set current PSP
2018-12-17T22:46:28.160866128Z 48 PC: 17bde | Get DOS version
2018-12-17T22:46:28.163117304Z 99 PC: 1e3c0 | Get DBCS lead byte table pointer
2018-12-17T22:46:28.167173062Z 101 PC: 17c64 | Get extended country info
2018-12-17T22:46:28.169042958Z 99 PC: 17c6a | Get DBCS lead byte table pointer
2018-12-17T22:46:28.170932047Z 74 PC: 17ccc | Reallocate memory
2018-12-17T22:46:28.173969008Z 25 PC: 17d03 | Get default drive
2018-12-17T22:46:28.175387676Z 37 PC: 177c3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:46:28.176765104Z 37 PC: 177ca | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:28.179962071Z 37 PC: 177d1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:28.184292729Z 74 PC: 1696c | Reallocate memory
2018-12-17T22:46:28.185777276Z 72 PC: 169ad | Allocate memory
2018-12-17T22:46:28.187892172Z 72 PC: 169e5 | Allocate memory
2018-12-17T22:46:28.192128643Z 72 PC: 169ed | Allocate memory