Sample viewer

vx.netlux.org/Trojan.DOS.Adidas

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:59.656671715Z 53 PC: 13316 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:59.664585996Z 53 PC: 13316 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:59.666129466Z 53 PC: 13316 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:59.667690431Z 53 PC: 13316 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:59.669586236Z 53 PC: 13316 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:59.670662481Z 53 PC: 13316 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:59.671676067Z 53 PC: 13316 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:59.673526226Z 53 PC: 13316 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:59.674861359Z 53 PC: 13316 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:59.67608226Z 53 PC: 13316 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:59.678714447Z 53 PC: 13316 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:59.679984722Z 53 PC: 13316 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:59.681600842Z 53 PC: 13316 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:59.6847926Z 53 PC: 13316 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:59.685997503Z 53 PC: 13316 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:59.687016364Z 53 PC: 13316 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:59.688683617Z 53 PC: 13316 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:59.689924943Z 53 PC: 13316 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:59.691021568Z 37 PC: 1332b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:59.693576017Z 37 PC: 13333 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:59.695646367Z 37 PC: 1333b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:59.696891299Z 37 PC: 13343 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:59.698516843Z 68 PC: 13688 | I/O control for devices (Set for = '')
2018-12-17T22:48:59.725347346Z 37 PC: 12c27 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:59.727008845Z 53 PC: 131ba | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:48:59.72975056Z 37 PC: 131d6 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:48:59.731344839Z 53 PC: 131ec | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:59.732800404Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:59.734221579Z 53 PC: 131ec | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:59.743252322Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:59.744315885Z 53 PC: 131ec | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:59.745418712Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:59.74845003Z 53 PC: 131ec | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:59.749884664Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:59.751380465Z 53 PC: 131ec | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:59.755288585Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:59.756712777Z 53 PC: 131ec | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:59.758254195Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:59.761705042Z 53 PC: 131ec | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:59.763125833Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:59.765170022Z 53 PC: 131ec | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:59.768667544Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:59.770136514Z 53 PC: 131ec | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:59.771512793Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:59.773685671Z 53 PC: 131ec | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:59.782452216Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:59.783846353Z 53 PC: 131ec | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:59.786207738Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:59.789902856Z 53 PC: 131ec | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:59.794599242Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:59.796961861Z 53 PC: 131ec | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:59.798193744Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:59.799336472Z 53 PC: 131ec | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:59.80126946Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:59.802370789Z 53 PC: 131ec | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:59.803437336Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:59.804905421Z 53 PC: 131ec | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:59.806141869Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:59.807227396Z 53 PC: 131ec | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:59.808553234Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:59.809848549Z 53 PC: 131ec | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:59.810915764Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:59.812387826Z 41 PC: 1328e | Parse filename
2018-12-17T22:48:59.814184881Z 41 PC: 1329c | Parse filename
2018-12-17T22:48:59.815572504Z 75 PC: 132a7 | Execute program
2018-12-17T22:48:59.825197735Z 53 PC: 131ec | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:59.826697895Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:59.828046639Z 53 PC: 131ec | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:59.82996051Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:48:59.831803479Z 53 PC: 131ec | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:59.833239632Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:48:59.834842986Z 53 PC: 131ec | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:59.836743046Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:59.83789151Z 53 PC: 131ec | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:59.83901169Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:59.841168108Z 53 PC: 131ec | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:59.842350741Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:48:59.843474174Z 53 PC: 131ec | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:59.84569689Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:48:59.846899816Z 53 PC: 131ec | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:59.848011885Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:48:59.850280143Z 53 PC: 131ec | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:59.852018268Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:48:59.853598036Z 53 PC: 131ec | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:59.856259164Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:48:59.857366449Z 53 PC: 131ec | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:59.858777814Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:48:59.860962506Z 53 PC: 131ec | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:59.862219795Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:48:59.863395876Z 53 PC: 131ec | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:59.865740084Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:48:59.867196137Z 53 PC: 131ec | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:59.868592244Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:48:59.870360866Z 53 PC: 131ec | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:59.871572595Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:48:59.872590684Z 53 PC: 131ec | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:59.874631511Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:48:59.876047132Z 53 PC: 131ec | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:59.877750381Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:48:59.880268552Z 53 PC: 131ec | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:59.881807532Z 37 PC: 131f5 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:48:59.88341936Z 49 PC: 13229 | Terminate and stay resident (Return code = '0' | Memory size = '402')