Sample viewer

vx.netlux.org/Trojan.DOS.Stuck

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:11.90076205Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:11.902571407Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:11.904630792Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:11.90687093Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:11.908545011Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:11.913839823Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:11.915296585Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:11.916833953Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:11.918740238Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:11.91992301Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:11.921147479Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:11.92373026Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:11.924924336Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:11.926122465Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:11.927876731Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:11.929070496Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:11.930260038Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:11.931965305Z 53 PC: 134a6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:11.934355774Z 37 PC: 134bb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:11.936254983Z 37 PC: 134c3 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:11.942107287Z 37 PC: 134cb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:11.944800993Z 37 PC: 134d3 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:11.946520105Z 68 PC: 13818 | I/O control for devices (Set for = '')
2018-12-17T22:48:11.974952298Z 37 PC: 12ed7 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:11.979896664Z 65 PC: 13c83 | Delete file (Filename = 'c:\windows\system\desk.cpl')
2018-12-17T22:48:11.995825051Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:11.997438592Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:11.999195966Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:12.000658753Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:12.001989969Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:12.003399181Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:12.004621725Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:12.005685531Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:12.00749524Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:12.008935267Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:12.010383278Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:12.012635858Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:12.014283663Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:12.015656495Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:12.018940986Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:12.020618253Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:12.022237016Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:12.024393559Z 37 PC: 135b5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:12.025766898Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.028116411Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.03151598Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.033818446Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.038243055Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.041241426Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.044613932Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.046887742Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.049367125Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.05163496Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.053608616Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.055603653Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.058960211Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.061156429Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.06268675Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.065199909Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.068059535Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.069710677Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.072498982Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.074891131Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.077655838Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.081002891Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.083590879Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.08614639Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.089337334Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.09244556Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.096132476Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.106295715Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.108774102Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.11122793Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.114256194Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.11677322Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.119986787Z 6 PC: 1363c | Direct console I/O
2018-12-17T22:48:12.122626608Z 76 PC: 135f4 | Terminate with return code (Return code = '2')