Sample viewer

vx.netlux.org/Trojan.DOS.EraseEXE.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:22.478591706Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:22.481065864Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:22.483887399Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:22.485645831Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:22.487335721Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:22.49482863Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:22.49630049Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:22.497740804Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:22.500013497Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:22.501308946Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:22.502626431Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:22.504819916Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:22.506733877Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:22.50869976Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:22.511942214Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:22.514904788Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:22.517467121Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:22.519922161Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:22.522502219Z 53 PC: 13b8a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:22.525007118Z 37 PC: 13b9f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:22.526746107Z 37 PC: 13ba7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:22.535245243Z 37 PC: 13baf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:22.539538342Z 37 PC: 13bb7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:22.541808973Z 68 PC: 144bc | I/O control for devices (Set for = '�J�ӻ')
2018-12-17T23:06:22.629128926Z 37 PC: 13291 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:22.631454517Z 67 PC: 13947 | Get or set file attributes
2018-12-17T23:06:22.638758749Z 67 PC: 13947 | Get or set file attributes
2018-12-17T23:06:22.650676152Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:22.651884259Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:06:22.653928783Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:22.655636045Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:06:22.657457412Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:22.659746071Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:06:22.661363392Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:22.662962485Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:22.665003249Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:22.666544685Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:22.668033423Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:22.670846417Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:22.673099065Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:22.674725242Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:06:22.676831329Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:22.678103347Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:06:22.694488404Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:22.695744305Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:06:22.697510199Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:22.699252527Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:06:22.700326654Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:22.70202638Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:06:22.703246384Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:22.70453376Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:06:22.706257291Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:22.707554054Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:06:22.70878519Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:22.710408549Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:06:22.711590862Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:22.712868208Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:06:22.714949392Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:22.716193416Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:06:22.71738485Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:22.719540528Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:06:22.721292759Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:22.722952599Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:06:22.725070927Z 53 PC: 13b04 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:22.726847342Z 37 PC: 13b0d | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:06:22.729040792Z 41 PC: 13a53 | Parse filename
2018-12-17T23:06:22.731588288Z 41 PC: 13a61 | Parse filename
2018-12-17T23:06:22.733553799Z 75 PC: 13a6c | Execute program
2018-12-17T23:06:22.750652248Z 80 PC: 16f09 | Set current PSP
2018-12-17T23:06:22.751724022Z 48 PC: 16f0e | Get DOS version
2018-12-17T23:06:22.753882297Z 99 PC: 1d6f0 | Get DBCS lead byte table pointer
2018-12-17T23:06:22.75705559Z 101 PC: 16f94 | Get extended country info
2018-12-17T23:06:22.758538662Z 99 PC: 16f9a | Get DBCS lead byte table pointer
2018-12-17T23:06:22.760291333Z 74 PC: 16ffc | Reallocate memory
2018-12-17T23:06:22.762201698Z 25 PC: 17033 | Get default drive
2018-12-17T23:06:22.763828499Z 37 PC: 16af3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:06:22.765833052Z 37 PC: 16afa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:22.76743546Z 37 PC: 16b01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:22.772634677Z 74 PC: 15c9c | Reallocate memory
2018-12-17T23:06:22.77494052Z 72 PC: 15cdd | Allocate memory
2018-12-17T23:06:22.776687723Z 72 PC: 15d15 | Allocate memory
2018-12-17T23:06:22.779485786Z 72 PC: 15d1d | Allocate memory