Sample viewer

vx.netlux.org/Trojan.DOS.KillCommand.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:05:18.329026652Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:05:18.331134026Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:18.332607601Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:05:18.334067339Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:05:18.336621015Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:05:18.338099202Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:05:18.339373778Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:05:18.343267041Z 68 PC: 12ee6 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:05:18.345121081Z 68 PC: 12ee6 | I/O control for devices (Set for = '')
2018-12-17T22:05:18.347434867Z 67 PC: 13fe8 | Get or set file attributes
2018-12-17T22:05:18.356618787Z 61 PC: 1478e | Open file (Filename = 'c:\windows\win.com')
2018-12-17T22:05:18.363625819Z 68 PC: 13d3d | I/O control for devices (Set for = ''')
2018-12-17T22:05:18.365063004Z 64 PC: 14615 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:05:19.492272241Z 68 PC: 12ee6 | I/O control for devices (Set for = 'ar fw WÀAr Fw7À0r 9w0SQ3333Xc ')
2018-12-17T22:05:19.494683747Z 64 PC: 14e48 | Write file or device (Write 16 bytes on handle 1)
2018-12-17T22:05:19.497990878Z 63 PC: 1309f | Read file or device (Read 512 bytes on handle 0)