Sample viewer

vx.netlux.org/Trojan.DOS.Killer

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:30.064123439Z 48 PC: 12a4c | Get DOS version
2018-12-17T21:59:30.066076958Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:30.067247319Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:59:30.068386956Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:59:30.07866191Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:59:30.080943523Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:30.083073077Z 74 PC: 12af4 | Reallocate memory
2018-12-17T21:59:30.08611131Z 68 PC: 13b4f | I/O control for devices (Set for = '�� ')
2018-12-17T21:59:30.089857111Z 68 PC: 13b4f | I/O control for devices (Set for = '�� ')
2018-12-17T21:59:30.096068798Z 28 PC: 13ad9 | Get allocation info for specified drive
2018-12-17T21:59:30.140991573Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:59:30.143173984Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:59:30.144584715Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:59:30.146070987Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:59:30.14823649Z 76 PC: 12b9c | Terminate with return code (Return code = '24')