Sample viewer

vx.netlux.org/Trojan.DOS.Waster.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:40.110190382Z 48 PC: 1595c | Get DOS version
2018-12-17T21:58:40.112031248Z 74 PC: 159ac | Reallocate memory
2018-12-17T21:58:40.113865045Z 48 PC: 15a10 | Get DOS version
2018-12-17T21:58:40.115082861Z 53 PC: 15a18 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:40.126886111Z 37 PC: 15a2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:40.128403335Z 53 PC: 18402 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:40.129468147Z 37 PC: 18412 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:58:40.131630807Z 53 PC: 18417 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:40.133247247Z 37 PC: 18427 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:40.134274161Z 53 PC: 16156 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:40.141522708Z 53 PC: 16156 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:40.142987211Z 53 PC: 16156 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:40.144304763Z 53 PC: 16156 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:40.156922058Z 53 PC: 16156 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:40.158229155Z 53 PC: 16156 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:40.1593376Z 53 PC: 16156 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:40.161825311Z 53 PC: 16156 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:40.163034033Z 53 PC: 16156 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:40.16398161Z 53 PC: 16156 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:40.172639457Z 53 PC: 16156 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:58:40.173848787Z 37 PC: 16185 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:58:40.17491516Z 37 PC: 16185 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:58:40.176357904Z 37 PC: 16185 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:58:40.177521876Z 37 PC: 16185 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:58:40.178505421Z 37 PC: 16185 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:58:40.190802903Z 37 PC: 16185 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:58:40.191687343Z 37 PC: 16185 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:58:40.192446361Z 37 PC: 16185 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:58:40.193752845Z 37 PC: 1618c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:58:40.194855529Z 37 PC: 16191 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:58:40.196092506Z 68 PC: 15abb | I/O control for devices (Set for = '݃ ')
2018-12-17T21:58:40.197875611Z 68 PC: 15abb | I/O control for devices
2018-12-17T21:58:40.199164357Z 68 PC: 15abb | I/O control for devices
2018-12-17T21:58:40.200394513Z 68 PC: 15abb | I/O control for devices
2018-12-17T21:58:40.202027144Z 68 PC: 15abb | I/O control for devices
2018-12-17T21:58:40.203649071Z 53 PC: 13bd2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:40.20463231Z 53 PC: 13bdf | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:58:40.206074517Z 53 PC: 13bec | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:40.207104776Z 37 PC: 13c01 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:40.208028959Z 37 PC: 13c09 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:58:40.209422052Z 37 PC: 13c11 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:40.210557899Z 53 PC: 14690 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T21:58:40.211539666Z 53 PC: 1469d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T21:58:40.21286947Z 53 PC: 146ac | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:58:40.214042281Z 37 PC: 146b9 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T21:58:40.214928565Z 53 PC: 146c0 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:58:40.216345636Z 37 PC: 146cd | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T21:58:40.217515574Z 53 PC: 146d9 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T21:58:40.221368574Z 48 PC: 1479b | Get DOS version
2018-12-17T21:58:40.222916322Z 68 PC: 13b48 | I/O control for devices (Set for = '')
2018-12-17T21:58:40.224151263Z 68 PC: 13b48 | I/O control for devices (Set for = '')
2018-12-17T21:58:40.225344024Z 51 PC: 13b66 | Get or set Ctrl-Break
2018-12-17T21:58:40.226524296Z 51 PC: 13b72 | Get or set Ctrl-Break