Sample viewer

vx.netlux.org/Trojan.DOS.EraseEXE.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:48.957116685Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:11:48.958575148Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:48.961023944Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:11:48.962944275Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:11:48.971705983Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:11:48.974621456Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:48.976417583Z 74 PC: 12af4 | Reallocate memory
2018-12-17T23:11:48.979320473Z 68 PC: 12ede | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T23:11:48.982823891Z 68 PC: 12ede | I/O control for devices (Set for = '')
2018-12-17T23:11:48.985738854Z 47 PC: 13795 | Get disk transfer address
2018-12-17T23:11:48.98728961Z 26 PC: 1379e | Set disk transfer address
2018-12-17T23:11:48.99063432Z 78 PC: 137a8 | Find first file
2018-12-17T23:11:48.998120018Z 26 PC: 137b1 | Set disk transfer address
2018-12-17T23:11:49.000427497Z 67 PC: 13585 | Get or set file attributes
2018-12-17T23:11:49.007301985Z 61 PC: 13f66 | Open file (Filename = '')
2018-12-17T23:11:49.016600653Z 68 PC: 131d7 | I/O control for devices (Set for = '')
2018-12-17T23:11:49.018581428Z 68 PC: 12ede | I/O control for devices
2018-12-17T23:11:49.021462395Z 67 PC: 13585 | Get or set file attributes
2018-12-17T23:11:49.028937413Z 61 PC: 13f66 | Open file (Filename = 'vG�>�')
2018-12-17T23:11:49.035978775Z 68 PC: 131d7 | I/O control for devices (Set for = '')
2018-12-17T23:11:49.038051643Z 64 PC: 13ded | Write file or device (Write 0 bytes on handle 6)
2018-12-17T23:11:49.054198069Z 68 PC: 12ede | I/O control for devices
2018-12-17T23:11:49.057032379Z 63 PC: 1305d | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:11:49.065894816Z 63 PC: 1305d | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:11:49.071270696Z 81 PC: 122cc | Get current PSP
2018-12-17T23:11:49.072795213Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T23:11:49.075062487Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T23:11:49.083276123Z 89 PC: 12459 | Get extended error info
2018-12-17T23:11:49.085075267Z 2 PC: 1268d | Character output (Char = '53')
2018-12-17T23:11:49.087450794Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T23:11:49.091035666Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T23:11:49.094319482Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T23:11:49.09695623Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T23:11:49.099603178Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T23:11:49.10257653Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.104877107Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T23:11:49.107295204Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T23:11:49.110537141Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T23:11:49.112815005Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.115520503Z 2 PC: 1268d | Character output (Char = '66')
2018-12-17T23:11:49.118990559Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T23:11:49.121629031Z 2 PC: 1268d | Character output (Char = '75')
2018-12-17T23:11:49.124237826Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T23:11:49.128475185Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T23:11:49.131715599Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.134578393Z 2 PC: 126da | Character output (Char = '72')
2018-12-17T23:11:49.138027831Z 2 PC: 126da | Character output (Char = '65')
2018-12-17T23:11:49.141118633Z 2 PC: 126da | Character output (Char = '61')
2018-12-17T23:11:49.14419053Z 2 PC: 126da | Character output (Char = '64')
2018-12-17T23:11:49.147512958Z 2 PC: 126da | Character output (Char = '69')
2018-12-17T23:11:49.151322142Z 2 PC: 126da | Character output (Char = '6e')
2018-12-17T23:11:49.153805913Z 2 PC: 126da | Character output (Char = '67')
2018-12-17T23:11:49.156338025Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.159666504Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T23:11:49.162300037Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T23:11:49.164980588Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T23:11:49.168305621Z 2 PC: 1268d | Character output (Char = '76')
2018-12-17T23:11:49.170696166Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T23:11:49.17489331Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.178526112Z 2 PC: 126ce | Character output (Char = '41')
2018-12-17T23:11:49.181100744Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T23:11:49.183348972Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T23:11:49.18809643Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T23:11:49.190544614Z 2 PC: 1268d | Character output (Char = '62')
2018-12-17T23:11:49.192839931Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T23:11:49.196025642Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T23:11:49.19840146Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T23:11:49.200750277Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T23:11:49.20331497Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.206333086Z 2 PC: 1268d | Character output (Char = '52')
2018-12-17T23:11:49.208975295Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T23:11:49.211701863Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T23:11:49.214646169Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T23:11:49.216950764Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T23:11:49.219368861Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T23:11:49.222571404Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.225037612Z 2 PC: 1268d | Character output (Char = '49')
2018-12-17T23:11:49.228096404Z 2 PC: 1268d | Character output (Char = '67')
2018-12-17T23:11:49.231428831Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T23:11:49.23385821Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T23:11:49.236168305Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T23:11:49.240365388Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T23:11:49.243043835Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T23:11:49.24683802Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T23:11:49.252964823Z 2 PC: 1268d | Character output (Char = '46')
2018-12-17T23:11:49.255504649Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T23:11:49.25875977Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T23:11:49.262252038Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T23:11:49.264729066Z 2 PC: 1268d | Character output (Char = '3f')
2018-12-17T23:11:49.267075529Z 12 PC: 12581 | Flush input buffer and input