Sample viewer

vx.netlux.org/Trojan.DOS.Erase26.d1

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:46.623891333Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:10:46.626315952Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:46.627489104Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:10:46.628672122Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:10:46.630964695Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:10:46.63212741Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:46.636193631Z 74 PC: 12af4 | Reallocate memory
2018-12-17T23:10:46.641976811Z 68 PC: 12f6c | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T23:10:46.644239203Z 68 PC: 12f6c | I/O control for devices (Set for = '')
2018-12-17T23:10:46.646645394Z 42 PC: 12df9 | Get date 0x12df9: mov word ptr [si], cx
0x12dfb: mov word ptr [si + 2], dx
0x12dfe: pop si
0x12dff: pop bp
0x12e00: ret
0x12e01: push bp
0x12e02: mov bp, sp
0x12e04: push si
0x12e05: mov si, word ptr [bp + 4]
0x12e08: mov ah, 0x2c
0x12e0a: int 0x21
0x12e0c: mov word ptr [si], cx
0x12e0e: mov word ptr [si + 2], dx
0x12e11: pop si
0x12e12: pop bp
0x12e13: ret
0x12e14: push bp
0x12e15: mov bp, sp
0x12e17: push word ptr [bp + 4]
0x12e1a: mov al, 0
2018-12-17T23:10:46.649062477Z 44 PC: 12e0c | Get time 0x12e0c: mov word ptr [si], cx
0x12e0e: mov word ptr [si + 2], dx
0x12e11: pop si
0x12e12: pop bp
0x12e13: ret
0x12e14: push bp
0x12e15: mov bp, sp
0x12e17: push word ptr [bp + 4]
0x12e1a: mov al, 0
0x12e1c: push ax
0x12e1d: call 0x12e24
0x12e20: pop cx
0x12e21: pop cx
0x12e22: pop bp
0x12e23: ret
0x12e24: push bp
0x12e25: mov bp, sp
0x12e27: push si
0x12e28: mov si, word ptr [bp + 6]
0x12e2b: push ds
2018-12-17T23:10:46.654081725Z 28 PC: 12e33 | Get allocation info for specified drive
2018-12-17T23:10:46.693561701Z 37 PC: 12c36 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:46.694853276Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:10:46.697031314Z 37 PC: 12c4c | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:10:46.698591433Z 37 PC: 12c57 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:10:46.70023428Z 76 PC: 12be0 | Terminate with return code (Return code = '0')