Sample viewer

vx.netlux.org/Trojan.DOS.KillFiles.t

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:13:37.583646736Z 48 PC: 1a583 | Get DOS version
2018-12-17T22:13:37.592746981Z 48 PC: 13151 | Get DOS version
2018-12-17T22:13:37.594535493Z 55 PC: 13175 | Get or set switch character
2018-12-17T22:13:37.595906821Z 68 PC: 13356 | I/O control for devices (Set for = ')$')
2018-12-17T22:13:37.606572703Z 68 PC: 13356 | I/O control for devices (Set for = '')
2018-12-17T22:13:37.60799683Z 51 PC: 17e17 | Get or set Ctrl-Break
2018-12-17T22:13:37.608788057Z 51 PC: 17e23 | Get or set Ctrl-Break
2018-12-17T22:13:37.610038999Z 53 PC: 17e2f | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:13:37.611253855Z 53 PC: 17e3d | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:13:37.612413586Z 53 PC: 17e4b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:37.614209302Z 37 PC: 17e62 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:13:37.615534799Z 37 PC: 17e6b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:13:37.616656874Z 37 PC: 17e74 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:37.618423652Z 53 PC: 15961 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:13:37.619858527Z 53 PC: 1596f | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:13:37.621493379Z 53 PC: 1597e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:13:37.623710737Z 37 PC: 1598b | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:13:37.625035986Z 53 PC: 15992 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:13:37.62621577Z 37 PC: 1599f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:13:37.628112668Z 53 PC: 159ac | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:13:37.633196953Z 48 PC: 15a26 | Get DOS version
2018-12-17T22:13:37.635541828Z 44 PC: 150b4 | Get time 0x150b4: mov al, 0x3c
0x150b6: mul ch
0x150b8: xor ch, ch
0x150ba: add ax, cx
0x150bc: mov bx, ax
0x150be: lcall 0x12bd:0x1df5
0x150c3: mov ax, 0x3c
0x150c6: call 0x150e9
0x150c9: mov al, dh
0x150cb: mov ah, 1
0x150cd: call 0x150e9
0x150d0: mov ax, 0x64
0x150d3: call 0x150e9
0x150d6: mov al, dl
0x150d8: mov ah, 1
0x150da: call 0x150e9
0x150dd: mov ah, 2
0x150df: mov al, 0x64
0x150e1: call 0x150e9
0x150e4: pop dx
2018-12-17T22:13:37.643963713Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:37.645828121Z 26 PC: 14491 | Set disk transfer address
2018-12-17T22:13:37.647419852Z 78 PC: 14498 | Find first file
2018-12-17T22:13:37.653813806Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:37.657186953Z 65 PC: 143f6 | Delete file (Filename = 'SLEEP.COM')
2018-12-17T22:13:38.243078532Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.253562168Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.256371139Z 65 PC: 143f6 | Delete file (Filename = 'PRINT.S')
2018-12-17T22:13:38.267758176Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.271138375Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.273589499Z 65 PC: 143f6 | Delete file (Filename = 'PRINT.COM')
2018-12-17T22:13:38.286529835Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.289853688Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.292863256Z 65 PC: 143f6 | Delete file (Filename = 'HELLO.COM')
2018-12-17T22:13:38.305231284Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.308735092Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.31173427Z 65 PC: 143f6 | Delete file (Filename = 'PHANG.COM')
2018-12-17T22:13:38.322608786Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.325590094Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.328089808Z 65 PC: 143f6 | Delete file (Filename = 'PRINTA~1.COM')
2018-12-17T22:13:38.338906892Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.341886349Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.34504618Z 65 PC: 143f6 | Delete file (Filename = 'MANDEL.COM')
2018-12-17T22:13:38.355832802Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.358783649Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.362235697Z 65 PC: 143f6 | Delete file (Filename = 'PAH.COM')
2018-12-17T22:13:38.373059429Z 79 PC: 143fc | Find next file
2018-12-17T22:13:38.376066904Z 25 PC: 17262 | Get default drive
2018-12-17T22:13:38.378849958Z 65 PC: 143f6 | Delete file (Filename = 'TEST.EXE')
2018-12-17T22:13:38.389917956Z 79 PC: 143fc | Find next file