Sample viewer

vx.netlux.org/Trojan.DOS.UseKill

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:16.554537401Z 53 PC: 14bdb | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:16.555983003Z 53 PC: 14be8 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:14:16.556978895Z 53 PC: 14bf5 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:16.557943553Z 53 PC: 14c02 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:16.559347373Z 53 PC: 14c0f | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:14:16.560655483Z 37 PC: 14c22 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:14:16.56155488Z 37 PC: 14c2a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:14:16.562885981Z 37 PC: 14c32 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:14:16.564192348Z 68 PC: 15363 | I/O control for devices (Set for = '')
2018-12-17T22:14:16.640499372Z 53 PC: 145af | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:16.641883071Z 37 PC: 145c2 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:14:16.644134208Z 42 PC: 144ab | Get date 0x144ab: pushf
0x144ac: push es
0x144ad: push di
0x144ae: push bp
0x144af: mov bp, sp
0x144b1: les di, ptr [bp + 0x10]
0x144b4: cld
0x144b5: stosw word ptr es:[di], ax
0x144b6: mov ax, bx
0x144b8: stosw word ptr es:[di], ax
0x144b9: mov ax, cx
0x144bb: stosw word ptr es:[di], ax
0x144bc: mov ax, dx
0x144be: stosw word ptr es:[di], ax
0x144bf: pop ax
0x144c0: stosw word ptr es:[di], ax
0x144c1: mov ax, si
0x144c3: stosw word ptr es:[di], ax
0x144c4: pop ax
0x144c5: stosw word ptr es:[di], ax
2018-12-17T22:14:16.844553524Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:16.847125195Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:16.854819122Z 14 PC: 15aaa | Set default drive (Drive = 'A')
2018-12-17T22:14:16.856464174Z 59 PC: 15b08 | Change current directory
2018-12-17T22:14:16.861216486Z 54 PC: 144ab | Get free disk space
2018-12-17T22:14:16.87168327Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:16.877772733Z 60 PC: 157b3 | Create or truncate file
2018-12-17T22:14:16.894964435Z 62 PC: 15803 | Close file
2018-12-17T22:14:16.898070608Z 61 PC: 157b3 | Open file (Filename = 'filename.dat')
2018-12-17T22:14:16.905332781Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.906696166Z 78 PC: 144ab | Find first file
2018-12-17T22:14:16.913568163Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.91492793Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.918118004Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:16.922860626Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.924063973Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.927863137Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.929831962Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.932987246Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.934168604Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.93802541Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:16.941401026Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.94288889Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.94731525Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.948617499Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.951861241Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:16.955664131Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.956905364Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.960309562Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.962295791Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.965462204Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:16.968355871Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.970054725Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.974136262Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.975348593Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.979251977Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.980712445Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.98381781Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:16.987367328Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.98864468Z 79 PC: 144ab | Find next file
2018-12-17T22:14:16.991915954Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:16.995690154Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:16.997148471Z 79 PC: 144ab | Find next file
2018-12-17T22:14:17.000453469Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:17.004208771Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:17.005642717Z 79 PC: 144ab | Find next file
2018-12-17T22:14:17.008915114Z 64 PC: 15881 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:14:17.012942845Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:17.01432961Z 79 PC: 144ab | Find next file
2018-12-17T22:14:17.017988075Z 26 PC: 144ab | Set disk transfer address
2018-12-17T22:14:17.01986469Z 79 PC: 144ab | Find next file
2018-12-17T22:14:17.026792787Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.028510037Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.031805145Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.033682172Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.039422578Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.040856411Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.045066685Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.051401632Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.061771935Z 61 PC: 157b3 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:14:17.068329151Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.069714048Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.071339482Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.07268711Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.074093881Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.07617233Z 63 PC: 15881 | Read file or device (Read 10 bytes on handle 6)
2018-12-17T22:14:17.082316034Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.084309515Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.094301766Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.095808342Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.098286556Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.100114775Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.106179417Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.107094883Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.111971437Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.117751534Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.127274826Z 61 PC: 157b3 | Open file (Filename = 'PAH.COM')
2018-12-17T22:14:17.134215421Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.136144865Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.137408975Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.138777461Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.140325516Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.149643295Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.151685773Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.153140323Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.155551655Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.157472099Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.163943145Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.16517249Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.169247967Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.180982393Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.191030826Z 61 PC: 157b3 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:14:17.197742232Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.204814138Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.20619277Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.207568076Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.209260197Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.218936898Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.220765672Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.222230495Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.228520214Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.230287244Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.236312453Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.237674576Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.247265838Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.257922439Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.267988045Z 61 PC: 157b3 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:14:17.275031872Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.277188701Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.279426793Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.280979477Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.283440987Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.296171841Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.298118763Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.300593227Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.307036389Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.308879518Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.315820503Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.316751299Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.320851324Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.327035661Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.337274216Z 61 PC: 157b3 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:14:17.343915355Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.346342695Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.347636506Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.350553838Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.352342917Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.361913716Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.363684298Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.365187108Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.367594622Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.370542518Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.376989938Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.377919494Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.382497951Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.388178455Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.397626152Z 61 PC: 157b3 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:14:17.405122818Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.406578341Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.407768793Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.409506525Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.411028475Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.421265741Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.423467663Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.424619785Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.42687732Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.431057879Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.435340492Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.436454536Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.440531862Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.451580309Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.461291316Z 61 PC: 157b3 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:14:17.468249834Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.469740184Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.470940173Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.472957838Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.47448699Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.484188762Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.486678706Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.487949367Z 63 PC: 15881 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:14:17.494418498Z 66 PC: 158e0 | Move file pointer
2018-12-17T22:14:17.49747495Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.503766251Z 25 PC: 15a4d | Get default drive
2018-12-17T22:14:17.505127591Z 71 PC: 15a60 | Get current directory
2018-12-17T22:14:17.517238898Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.52654556Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.540791898Z 61 PC: 157b3 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:14:17.548728368Z 87 PC: 144ab | Get or set file date and time
2018-12-17T22:14:17.550269022Z 66 PC: 1594c | Move file pointer
2018-12-17T22:14:17.551542018Z 66 PC: 1595a | Move file pointer
2018-12-17T22:14:17.552929517Z 66 PC: 15968 | Move file pointer
2018-12-17T22:14:17.554511158Z 67 PC: 144ab | Get or set file attributes
2018-12-17T22:14:17.56425047Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.566727788Z 62 PC: 15803 | Close file
2018-12-17T22:14:17.576146075Z 65 PC: 15985 | Delete file (Filename = 'filename.dat')