Sample viewer

vx.netlux.org/Trojan.DOS.DelFiles.i

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:04.829775529Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:04.831779617Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:04.834314163Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:04.835970829Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:04.837800559Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:04.840286955Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:04.842574628Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:04.844709272Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:04.847051195Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:04.848538512Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:04.850131989Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:04.852465857Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:04.853926013Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:04.8552805Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:04.857283376Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:04.859053565Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:04.860664765Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:04.863299409Z 53 PC: 134e6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:04.8660917Z 37 PC: 134fb | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:04.867566593Z 37 PC: 13503 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:04.869332925Z 37 PC: 1350b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:04.875343578Z 37 PC: 13513 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:04.877824162Z 68 PC: 13858 | I/O control for devices (Set for = '')
2018-12-17T22:56:04.915477127Z 37 PC: 12f17 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:04.924863909Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:04.926774973Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:04.934061495Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:04.967767628Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:04.981764198Z 65 PC: 13cc3 | Delete file (Filename = 'SLEEP.COM')
2018-12-17T22:56:04.99359757Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:04.996034663Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.003152137Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.013991751Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.027761635Z 65 PC: 13cc3 | Delete file (Filename = 'PRINT.S')
2018-12-17T22:56:05.041615917Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.04287817Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.057062904Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.070792392Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.090667075Z 65 PC: 13cc3 | Delete file (Filename = 'PRINT.COM')
2018-12-17T22:56:05.102063456Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.104267681Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.111273996Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.122583292Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.136681333Z 65 PC: 13cc3 | Delete file (Filename = 'HELLO.COM')
2018-12-17T22:56:05.147880303Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.149334006Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.156881108Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.167822072Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.183573732Z 65 PC: 13cc3 | Delete file (Filename = 'PHANG.COM')
2018-12-17T22:56:05.194796646Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.19643116Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.203422467Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.21427756Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.228917539Z 65 PC: 13cc3 | Delete file (Filename = 'PRINTA~1.COM')
2018-12-17T22:56:05.24311685Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.24491428Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.25274232Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.263319821Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.276768591Z 65 PC: 13cc3 | Delete file (Filename = 'MANDEL.COM')
2018-12-17T22:56:05.291191893Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.292742539Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.305175278Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.31673217Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.330313229Z 65 PC: 13cc3 | Delete file (Filename = 'PAH.COM')
2018-12-17T22:56:05.341589394Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.344041705Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.35125534Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.36556563Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.379001265Z 65 PC: 13cc3 | Delete file (Filename = 'TEST.EXE')
2018-12-17T22:56:05.387795241Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.388925607Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.393753686Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.398960758Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.409429965Z 65 PC: 13cc3 | Delete file (Filename = 'TEST.EXE')
2018-12-17T22:56:05.431179754Z 59 PC: 13dfa | Change current directory
2018-12-17T22:56:05.436880644Z 26 PC: 12de7 | Set disk transfer address
2018-12-17T22:56:05.438390564Z 78 PC: 12df3 | Find first file
2018-12-17T22:56:05.445232249Z 67 PC: 12db6 | Get or set file attributes
2018-12-17T22:56:05.452610994Z 60 PC: 13b7a | Create or truncate file
2018-12-17T22:56:05.464907979Z 65 PC: 13cc3 | Delete file (Filename = 'TEST.EXE')
2018-12-17T22:56:05.477259505Z 60 PC: 1383f | Create or truncate file
2018-12-17T22:56:05.494032356Z 68 PC: 13858 | I/O control for devices (Set for = 'Command.com')
2018-12-17T22:56:05.496621504Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.504649941Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.508705678Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.512745064Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.516512068Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.526360117Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.531055396Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.534865832Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.538705602Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.548267743Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.551767755Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.555993902Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.560176096Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.56924529Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.572603756Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.577967472Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.586147354Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.60011533Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.605799269Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.610328215Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.613998076Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.624021945Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.628776797Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.632379481Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.636061074Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.646409614Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.650259985Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.654327564Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.660538403Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.673047215Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.676774264Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.681410031Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.685714996Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.695178041Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.698782279Z 64 PC: 13936 | Write file or device (Write 128 bytes on handle 16)
2018-12-17T22:56:05.703507855Z 64 PC: 13936 | Write file or device (Write 65 bytes on handle 16)
2018-12-17T22:56:05.706769388Z 62 PC: 13975 | Close file
2018-12-17T22:56:05.723811405Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:05.726590531Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:05.728443025Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:05.730198586Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:56:05.732825406Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:05.735149266Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:56:05.737582942Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:05.740467977Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:05.742682001Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:05.744414799Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:05.746254989Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:05.749341133Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:56:05.751021663Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:05.752868716Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:56:05.755682497Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:05.757567792Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:56:05.759230499Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:05.762279653Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:56:05.764124211Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:05.765914398Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:56:05.768690007Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:05.77136115Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:56:05.77302578Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:05.775683187Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:56:05.777714517Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:05.779315548Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:56:05.781780042Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:05.783817714Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:56:05.785497063Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:05.788029154Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:56:05.790154591Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:05.791740012Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:56:05.793528014Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:05.796173269Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:56:05.79784904Z 53 PC: 12e4e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:56:05.799433529Z 37 PC: 12e57 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')