Sample viewer

vx.netlux.org/Trojan.DOS.Evil.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:21.643392199Z 48 PC: 13161 | Get DOS version
2018-12-17T23:05:21.647929202Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:21.649982489Z 74 PC: 12d49 | Reallocate memory
2018-12-17T23:05:21.651918379Z 74 PC: 12d4d | Reallocate memory
2018-12-17T23:05:21.65653651Z 37 PC: 15ce9 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:21.663799808Z 26 PC: 162df | Set disk transfer address
2018-12-17T23:05:21.664975131Z 78 PC: 162df | Find first file
2018-12-17T23:05:21.671813814Z 65 PC: 162df | Delete file (Filename = 'c:\IO.SYS')
2018-12-17T23:05:22.025559057Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.029431933Z 65 PC: 162df | Delete file (Filename = 'c:\MSDOS.SYS')
2018-12-17T23:05:22.043230352Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.046925444Z 65 PC: 162df | Delete file (Filename = 'c:\COMMAND.COM')
2018-12-17T23:05:22.058756888Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.061953833Z 65 PC: 162df | Delete file (Filename = 'c:\CONFIG.SYS')
2018-12-17T23:05:22.076084381Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.079505931Z 65 PC: 162df | Delete file (Filename = 'c:\AUTOEXEC.BAT')
2018-12-17T23:05:22.091280664Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.095562712Z 26 PC: 162df | Set disk transfer address
2018-12-17T23:05:22.097218618Z 78 PC: 162df | Find first file
2018-12-17T23:05:22.107857941Z 65 PC: 162df | Delete file (Filename = 'c:\dos\ATTRIB.EXE')
2018-12-17T23:05:22.122638729Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.126182206Z 65 PC: 162df | Delete file (Filename = 'c:\dos\CHKDSK.EXE')
2018-12-17T23:05:22.138147055Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.14226413Z 65 PC: 162df | Delete file (Filename = 'c:\dos\COUNTRY.SYS')
2018-12-17T23:05:22.153801768Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.15714296Z 65 PC: 162df | Delete file (Filename = 'c:\dos\COUNTRY.TXT')
2018-12-17T23:05:22.16918623Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.172613566Z 65 PC: 162df | Delete file (Filename = 'c:\dos\DEBUG.EXE')
2018-12-17T23:05:22.183737058Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.18621366Z 65 PC: 162df | Delete file (Filename = 'c:\dos\DOSSETUP.INI')
2018-12-17T23:05:22.194144761Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.196396326Z 65 PC: 162df | Delete file (Filename = 'c:\dos\DRVSPACE.BIN')
2018-12-17T23:05:22.203946097Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.206513182Z 65 PC: 162df | Delete file (Filename = 'c:\dos\EDIT.COM')
2018-12-17T23:05:22.213753284Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.215863193Z 65 PC: 162df | Delete file (Filename = 'c:\dos\EXPAND.EXE')
2018-12-17T23:05:22.223788005Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.226033098Z 65 PC: 162df | Delete file (Filename = 'c:\dos\FDISK.EXE')
2018-12-17T23:05:22.233364486Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.236263674Z 65 PC: 162df | Delete file (Filename = 'c:\dos\FORMAT.COM')
2018-12-17T23:05:22.243537624Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.245808032Z 65 PC: 162df | Delete file (Filename = 'c:\dos\KEYB.COM')
2018-12-17T23:05:22.253843721Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.256115106Z 65 PC: 162df | Delete file (Filename = 'c:\dos\KEYBOARD.SYS')
2018-12-17T23:05:22.263770002Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.266579132Z 65 PC: 162df | Delete file (Filename = 'c:\dos\MEM.EXE')
2018-12-17T23:05:22.274142895Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.2764379Z 65 PC: 162df | Delete file (Filename = 'c:\dos\NLSFUNC.EXE')
2018-12-17T23:05:22.284475502Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.287292672Z 65 PC: 162df | Delete file (Filename = 'c:\dos\README.TXT')
2018-12-17T23:05:22.295627572Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.29807108Z 65 PC: 162df | Delete file (Filename = 'c:\dos\NETWORKS.TXT')
2018-12-17T23:05:22.306028051Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.308367708Z 65 PC: 162df | Delete file (Filename = 'c:\dos\QBASIC.EXE')
2018-12-17T23:05:22.319428586Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.323763129Z 65 PC: 162df | Delete file (Filename = 'c:\dos\REPLACE.EXE')
2018-12-17T23:05:22.336135278Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.339613723Z 65 PC: 162df | Delete file (Filename = 'c:\dos\RESTORE.EXE')
2018-12-17T23:05:22.353567483Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.357138435Z 65 PC: 162df | Delete file (Filename = 'c:\dos\SCANDISK.EXE')
2018-12-17T23:05:22.676780934Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.681031164Z 65 PC: 162df | Delete file (Filename = 'c:\dos\SCANDISK.INI')
2018-12-17T23:05:22.74041277Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.743778988Z 65 PC: 162df | Delete file (Filename = 'c:\dos\SETUP.EXE')
2018-12-17T23:05:22.798463155Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.802136892Z 65 PC: 162df | Delete file (Filename = 'c:\dos\SYS.COM')
2018-12-17T23:05:22.850391207Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.855181405Z 65 PC: 162df | Delete file (Filename = 'c:\dos\XCOPY.EXE')
2018-12-17T23:05:22.929052001Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.932123801Z 65 PC: 162df | Delete file (Filename = 'c:\dos\DEFRAG.EXE')
2018-12-17T23:05:22.991723925Z 79 PC: 162df | Find next file
2018-12-17T23:05:22.995846272Z 65 PC: 162df | Delete file (Filename = 'c:\dos\DEFRAG.HLP')
2018-12-17T23:05:23.032075945Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.034589815Z 65 PC: 162df | Delete file (Filename = 'c:\dos\EGA.CPI')
2018-12-17T23:05:23.087037199Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.090629216Z 65 PC: 162df | Delete file (Filename = 'c:\dos\EGA2.CPI')
2018-12-17T23:05:23.145270744Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.150465845Z 65 PC: 162df | Delete file (Filename = 'c:\dos\EGA3.CPI')
2018-12-17T23:05:23.202462033Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.205117461Z 65 PC: 162df | Delete file (Filename = 'c:\dos\EMM386.EXE')
2018-12-17T23:05:23.258662929Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.263292149Z 65 PC: 162df | Delete file (Filename = 'c:\dos\ISO.CPI')
2018-12-17T23:05:23.319134685Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.321928012Z 65 PC: 162df | Delete file (Filename = 'c:\dos\KEYBRD2.SYS')
2018-12-17T23:05:23.3591136Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.363076119Z 65 PC: 162df | Delete file (Filename = 'c:\dos\MSCDEX.EXE')
2018-12-17T23:05:23.3753911Z 79 PC: 162df | Find next file
2018-12-17T23:05:23.377569668Z 65 PC: 162df | Delete file (Filename = 'c:\dos\QBASIC.INI')
2018-12-17T23:05:23.390762884Z 79 PC: 162df | Find next file