Sample viewer

vx.netlux.org/Trojan.DOS.KillCMOS.g

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:37.911121034Z 44 PC: 13a77 | Get time 0x13a77: mov byte ptr [0x466], cl
0x13a7b: mov word ptr [0x467], dx
0x13a7f: mov ax, ds
0x13a81: mov word ptr [0x47c], ax
0x13a84: mov word ptr [0x480], ax
0x13a87: mov word ptr [0x478], ax
0x13a8a: push ax
0x13a8b: mov ax, word ptr [2]
0x13a8e: mov word ptr [0xe43], ax
0x13a91: pop ax
0x13a92: call 0x14933
0x13a95: push es
0x13a96: call 0x17e04
0x13a99: pop es
0x13a9a: mov di, 0x80
0x13a9d: mov cl, byte ptr [di]
0x13a9f: inc di
0x13aa0: mov ch, 0
0x13aa2: jcxz 0x13acb
0x13aa4: cld
2018-12-17T22:51:37.91351429Z 81 PC: 17e0e | Get current PSP
2018-12-17T22:51:37.914539851Z 61 PC: 17e67 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:51:37.918802572Z 66 PC: 17ed2 | Move file pointer
2018-12-17T22:51:37.920282985Z 63 PC: 17eea | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:51:37.926379965Z 66 PC: 17f0f | Move file pointer
2018-12-17T22:51:37.927558652Z 63 PC: 17f1b | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:51:37.930105312Z 62 PC: 17e7d | Close file
2018-12-17T22:51:37.932098171Z 102 PC: 13ad0 | Get or set code page
2018-12-17T22:51:37.933630858Z 102 PC: 13ade | Get or set code page
2018-12-17T22:51:37.935343693Z 9 PC: 13ae8 | Display string (String= 'Cannot run Windows with current code page. Remove COUNTRY command from CONFIG.SYS and restart your computer. ')
2018-12-17T22:51:37.944113187Z 76 PC: 13aed | Terminate with return code (Return code = '255')