Sample viewer

vx.netlux.org/Trojan.DOS.DelSystem.f

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:06.32203281Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:06.32438023Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:11:06.326497126Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:06.328209612Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:06.335144062Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:06.336572719Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:06.346231579Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:11:06.34765403Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:11:06.349102253Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:11:06.356834678Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:11:06.358430018Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:11:06.359935445Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:11:06.363092195Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:11:06.364565789Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:11:06.366023608Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:11:06.368590893Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:11:06.370616742Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:11:06.372486265Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:06.37486928Z 53 PC: 12c4a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:11:06.376717827Z 37 PC: 12c5f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:06.378290163Z 37 PC: 12c67 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:06.380499108Z 37 PC: 12c6f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:06.382008141Z 37 PC: 12c77 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:11:06.384355404Z 68 PC: 13508 | I/O control for devices (Set for = '')
2018-12-17T23:11:06.387372308Z 64 PC: 13068 | Write file or device (Write 61 bytes on handle 1)
2018-12-17T23:11:06.392681728Z 86 PC: 1349d | Rename file
2018-12-17T23:11:06.747326848Z 63 PC: 13011 | Read file or device (Read 128 bytes on handle 0)