Sample viewer

vx.netlux.org/Trojan.DOS.DelAutoexec.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:58.974844867Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:54:58.977215998Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:58.978517185Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:54:58.97976396Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:54:58.982001189Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:54:58.983916802Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:58.985775218Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:54:58.989441584Z 68 PC: 12e0d | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:54:58.991484487Z 68 PC: 12e0d | I/O control for devices (Set for = '')
2018-12-17T22:54:58.993256841Z 67 PC: 132a0 | Get or set file attributes
2018-12-17T22:54:58.999846236Z 61 PC: 1366f | Open file (Filename = 'c:\autoexec.bat')
2018-12-17T22:54:59.006515161Z 68 PC: 13005 | I/O control for devices (Set for = '')
2018-12-17T22:54:59.008267788Z 65 PC: 12ec4 | Delete file (Filename = 'c:\autoexec.bat')
2018-12-17T22:54:59.685380384Z 62 PC: 132db | Close file
2018-12-17T22:54:59.689004221Z 37 PC: 12c36 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:59.69057751Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:54:59.69213518Z 37 PC: 12c4c | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:54:59.695067105Z 37 PC: 12c57 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:54:59.696840581Z 76 PC: 12be0 | Terminate with return code (Return code = '0')