Sample viewer

vx.netlux.org/Trojan.DOS.Xexe

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:41.884982763Z 74 PC: 1453b | Reallocate memory
2018-12-17T22:47:41.889220268Z 74 PC: 14b69 | Reallocate memory
2018-12-17T22:47:41.895861509Z 53 PC: 1392a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:41.897772814Z 53 PC: 1392a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:41.900404648Z 53 PC: 1392a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:41.906157235Z 53 PC: 1392a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:41.909183225Z 53 PC: 1392a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:41.911093754Z 53 PC: 1392a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:41.913506986Z 53 PC: 1392a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:41.915151228Z 53 PC: 1392a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:41.916819113Z 53 PC: 1392a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:41.918919875Z 53 PC: 1392a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:41.920311992Z 53 PC: 1392a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:41.921717175Z 53 PC: 1392a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:41.923869083Z 53 PC: 1392a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:41.925892214Z 53 PC: 1392a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:41.927593131Z 53 PC: 1392a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:41.929611972Z 53 PC: 1392a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:41.931060673Z 53 PC: 1392a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:41.932747583Z 53 PC: 1392a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:41.9355252Z 53 PC: 1392a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:41.936912813Z 37 PC: 1393f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:41.938380552Z 37 PC: 13947 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:41.940277018Z 37 PC: 1394f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:41.94712247Z 37 PC: 13957 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:41.949230203Z 68 PC: 142ea | I/O control for devices (Set for = '�j')
2018-12-17T22:47:42.027788825Z 37 PC: 13211 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:42.031540605Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:42.033349884Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:42.035072667Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:42.037438922Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:42.03886967Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:42.040273703Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:42.043417955Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:42.044932584Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:42.046404103Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:42.048749032Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:42.050204167Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:42.051628605Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:42.053142706Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:42.054878753Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:42.056190828Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:42.057537954Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:42.05909071Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:42.060825684Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:42.062524295Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:42.064528689Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:42.066252223Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:42.067941245Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:42.070656168Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:42.072316506Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:42.074010854Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:42.076457306Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:42.078419619Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:42.08012807Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:42.08371486Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:42.085245217Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:42.086657847Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:42.096864772Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:42.098982289Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:42.101441293Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:42.103677699Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:42.106892951Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:42.109227705Z 53 PC: 138a8 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:42.111393525Z 37 PC: 138b1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:42.130676266Z 41 PC: 1385f | Parse filename
2018-12-17T22:47:42.133727391Z 41 PC: 1386d | Parse filename
2018-12-17T22:47:42.135957814Z 75 PC: 13878 | Execute program
2018-12-17T22:47:42.176523572Z 80 PC: 196f9 | Set current PSP
2018-12-17T22:47:42.177577805Z 48 PC: 196fe | Get DOS version
2018-12-17T22:47:42.179451062Z 99 PC: 1fee0 | Get DBCS lead byte table pointer
2018-12-17T22:47:42.18845403Z 101 PC: 19784 | Get extended country info
2018-12-17T22:47:42.191100484Z 99 PC: 1978a | Get DBCS lead byte table pointer
2018-12-17T22:47:42.192895147Z 74 PC: 197ec | Reallocate memory
2018-12-17T22:47:42.195609616Z 25 PC: 19823 | Get default drive
2018-12-17T22:47:42.196944384Z 37 PC: 192e3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:47:42.198089305Z 37 PC: 192ea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:42.199349744Z 37 PC: 192f1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:42.202745549Z 74 PC: 1848c | Reallocate memory
2018-12-17T22:47:42.204077788Z 72 PC: 184cd | Allocate memory
2018-12-17T22:47:42.205610343Z 72 PC: 18505 | Allocate memory
2018-12-17T22:47:42.20819926Z 72 PC: 1850d | Allocate memory