Sample viewer

vx.netlux.org/Trojan.DOS.DelFiles.j

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:46.65735521Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:46.659515115Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:46.663280497Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:46.664440459Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:46.665852176Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:46.667874192Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:46.668979853Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:46.6700286Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:46.671609334Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:46.672710564Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:46.673938301Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:46.676095058Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:46.677473914Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:46.678828875Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:46.680796193Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:46.682361017Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:46.683821574Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:46.686607161Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:46.687917097Z 53 PC: 12e0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:46.689126337Z 37 PC: 12e1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:46.693206945Z 37 PC: 12e27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:46.69443301Z 37 PC: 12e2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:46.695535635Z 37 PC: 12e37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:46.697036577Z 68 PC: 1381a | I/O control for devices (Set for = 'u <')
2018-12-17T22:01:46.699201673Z 25 PC: 134ec | Get default drive
2018-12-17T22:01:46.700620396Z 71 PC: 134ff | Get current directory
2018-12-17T22:01:46.70384782Z 48 PC: 1345f | Get DOS version
2018-12-17T22:01:46.705870636Z 25 PC: 134ec | Get default drive
2018-12-17T22:01:46.70690805Z 71 PC: 134ff | Get current directory
2018-12-17T22:01:46.709797885Z 26 PC: 12d05 | Set disk transfer address
2018-12-17T22:01:46.711565663Z 78 PC: 12d11 | Find first file
2018-12-17T22:01:46.717364288Z 60 PC: 137fe | Create or truncate file
2018-12-17T22:01:47.072371732Z 68 PC: 1381a | I/O control for devices (Set for = 'u <')
2018-12-17T22:01:47.075714302Z 64 PC: 13203 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:01:47.077345024Z 62 PC: 13242 | Close file
2018-12-17T22:01:47.08235349Z 61 PC: 137fe | Open file (Filename = 'C:\dos.txt')
2018-12-17T22:01:47.088685804Z 68 PC: 1381a | I/O control for devices (Set for = 'u <')
2018-12-17T22:01:47.090043978Z 66 PC: 13869 | Move file pointer
2018-12-17T22:01:47.091559881Z 66 PC: 13880 | Move file pointer
2018-12-17T22:01:47.093369916Z 63 PC: 1388d | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:01:47.095098972Z 64 PC: 13203 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:01:47.101889301Z 62 PC: 13242 | Close file
2018-12-17T22:01:47.110822517Z 61 PC: 137fe | Open file (Filename = 'C:\autoexec.bat')
2018-12-17T22:01:47.116109584Z 68 PC: 1381a | I/O control for devices (Set for = 'u <')
2018-12-17T22:01:47.117628408Z 66 PC: 13869 | Move file pointer
2018-12-17T22:01:47.119812569Z 66 PC: 13880 | Move file pointer
2018-12-17T22:01:47.120972924Z 63 PC: 1388d | Read file or device (Read 128 bytes on handle 5)
2018-12-17T22:01:47.123293536Z 64 PC: 13203 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:01:47.126480422Z 62 PC: 13242 | Close file
2018-12-17T22:01:47.131210897Z 53 PC: 12d66 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:01:47.132279647Z 37 PC: 12d82 | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:01:47.13382156Z 49 PC: 12d9d | Terminate and stay resident (Return code = '0' | Memory size = '2893')