Sample viewer

vx.netlux.org/Trojan.DOS.Kevin.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:11:41.590740201Z 53 PC: 134ba | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:11:41.593030776Z 37 PC: 134d1 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:11:41.594595841Z 37 PC: 134e4 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:11:41.596675169Z 61 PC: 13532 | Open file (Filename = ' $not enough memory to load $invalid environment$invalid file $ $�a��������+�ٸ')
2018-12-17T22:11:41.611706511Z 61 PC: 13544 | Open file (Filename = ' $not enough memory to load $invalid environment$invalid file $ $�a��������+�ٸ')
2018-12-17T22:11:41.618673031Z 61 PC: 13568 | Open file (Filename = ' $not enough memory to load $invalid environment$invalid file $ $�a��������+�ٸ')
2018-12-17T22:11:41.628084485Z 64 PC: 132a6 | Write file or device (Write 17 bytes on handle 2)
2018-12-17T22:11:41.63118489Z 64 PC: 132a6 | Write file or device (Write 2 bytes on handle 2)
2018-12-17T22:11:41.635292688Z 64 PC: 132a6 | Write file or device (Write 11 bytes on handle 2)
2018-12-17T22:11:41.639109613Z 64 PC: 132a6 | Write file or device (Write 12 bytes on handle 2)
2018-12-17T22:11:41.642162115Z 64 PC: 132a6 | Write file or device (Write 2 bytes on handle 2)
2018-12-17T22:11:41.647951111Z 76 PC: 13280 | Terminate with return code (Return code = '255')