Sample viewer

vx.netlux.org/Trojan.DOS.EraseCMOS

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:14.224831355Z 53 PC: 12ada | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:14.226717721Z 53 PC: 12ada | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:14.227985966Z 53 PC: 12ada | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:02:14.229093705Z 53 PC: 12ada | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:14.230677532Z 53 PC: 12ada | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:14.231899593Z 53 PC: 12ada | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:14.233047798Z 53 PC: 12ada | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:14.234311487Z 53 PC: 12ada | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:14.236130246Z 53 PC: 12ada | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:14.246106845Z 53 PC: 12ada | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:14.247340696Z 53 PC: 12ada | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:14.25396644Z 53 PC: 12ada | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:14.255304793Z 53 PC: 12ada | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:14.256739455Z 53 PC: 12ada | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:14.260702172Z 53 PC: 12ada | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:14.262177538Z 53 PC: 12ada | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:14.263621069Z 53 PC: 12ada | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:02:14.266373473Z 53 PC: 12ada | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:02:14.267554126Z 53 PC: 12ada | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:02:14.26873253Z 37 PC: 12aef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:14.271563904Z 37 PC: 12af7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:14.272862911Z 37 PC: 12aff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:14.274143949Z 37 PC: 12b07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:02:14.276268663Z 68 PC: 12f62 | I/O control for devices (Set for = '�A��f��؎�6')
2018-12-17T23:02:14.278915107Z 64 PC: 12ef8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T23:02:14.280581147Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:02:14.282142791Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:02:14.283185503Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:02:14.284157422Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:14.285360829Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:02:14.286604158Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:14.287640619Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:02:14.288981133Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:02:14.290529468Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:02:14.291433017Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:02:14.292613569Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:02:14.294532853Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:02:14.295533149Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:02:14.297917952Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:02:14.299327091Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:02:14.300842665Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:02:14.311891952Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:02:14.313500546Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:02:14.314968213Z 37 PC: 12c31 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:02:14.316675473Z 76 PC: 12c70 | Terminate with return code (Return code = '0')