Sample viewer

vx.netlux.org/Trojan.DOS.KillFiles.x

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:40.930069189Z 48 PC: 12f37 | Get DOS version
2018-12-17T22:10:40.933503079Z 74 PC: 12cf6 | Reallocate memory
2018-12-17T22:10:40.935284277Z 74 PC: 12cfa | Reallocate memory
2018-12-17T22:10:40.978688944Z 74 PC: 15543 | Reallocate memory
2018-12-17T22:10:40.981571289Z 75 PC: 15653 | Execute program
2018-12-17T22:10:41.002076747Z 80 PC: 27e69 | Set current PSP
2018-12-17T22:10:41.002899726Z 48 PC: 27e6e | Get DOS version
2018-12-17T22:10:41.004350247Z 99 PC: 2e650 | Get DBCS lead byte table pointer
2018-12-17T22:10:41.007878339Z 101 PC: 27ef4 | Get extended country info
2018-12-17T22:10:41.00922649Z 99 PC: 27efa | Get DBCS lead byte table pointer
2018-12-17T22:10:41.010419318Z 74 PC: 27f5c | Reallocate memory
2018-12-17T22:10:41.013764994Z 25 PC: 27f93 | Get default drive
2018-12-17T22:10:41.014960371Z 37 PC: 27a53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:10:41.016154375Z 37 PC: 27a5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:41.017936774Z 37 PC: 27a61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:41.022230996Z 74 PC: 26bfc | Reallocate memory
2018-12-17T22:10:41.023527265Z 72 PC: 26c3d | Allocate memory
2018-12-17T22:10:41.029770795Z 72 PC: 26c75 | Allocate memory
2018-12-17T22:10:41.031320871Z 72 PC: 26c7d | Allocate memory