Sample viewer

vx.netlux.org/Trojan.DOS.DirKiller

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:16.437323671Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:58:16.438681061Z 53 PC: 12b88 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:16.439778751Z 53 PC: 12b95 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:16.442739301Z 53 PC: 12ba2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:58:16.443869307Z 53 PC: 12baf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:58:16.444991432Z 37 PC: 12bc3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:16.446811383Z 74 PC: 12ad6 | Reallocate memory
2018-12-17T22:58:16.449597855Z 68 PC: 13818 | I/O control for devices (Set for = '�1')
2018-12-17T22:58:16.451897566Z 74 PC: 13b7a | Reallocate memory
2018-12-17T22:58:16.460859071Z 74 PC: 13b7a | Reallocate memory
2018-12-17T22:58:16.462630439Z 68 PC: 13818 | I/O control for devices (Set for = 'Borland C++ - Copyright 1991 Borland Intl.')
2018-12-17T22:58:16.464675442Z 60 PC: 135a6 | Create or truncate file
2018-12-17T22:58:16.484277726Z 62 PC: 13582 | Close file
2018-12-17T22:58:16.488282363Z 37 PC: 12bcf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:16.490071788Z 37 PC: 12bda | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:16.49198414Z 37 PC: 12be5 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:58:16.495004034Z 37 PC: 12bf0 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:58:16.496297433Z 76 PC: 12b79 | Terminate with return code (Return code = '0')