Sample viewer

vx.netlux.org/Trojan.DOS.CMOSKiller.d

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:00.806609753Z 80 PC: 14b99 | Set current PSP
2018-12-17T22:18:00.807483629Z 81 PC: 162b5 | Get current PSP
2018-12-17T22:18:00.808296992Z 61 PC: 162e1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:18:00.817279661Z 63 PC: 1632d | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:18:00.819709748Z 66 PC: 163a0 | Move file pointer
2018-12-17T22:18:00.822097513Z 63 PC: 163ab | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:18:00.824754261Z 66 PC: 163a0 | Move file pointer
2018-12-17T22:18:00.835523093Z 63 PC: 163ab | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:18:00.842720687Z 63 PC: 16412 | Read file or device (Read 1584 bytes on handle 5)
2018-12-17T22:18:00.850392065Z 62 PC: 16312 | Close file
2018-12-17T22:18:00.853180313Z 81 PC: 162b5 | Get current PSP
2018-12-17T22:18:00.854640628Z 61 PC: 162e1 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:18:00.861727162Z 63 PC: 1632d | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:18:00.866038185Z 66 PC: 163a0 | Move file pointer
2018-12-17T22:18:00.867563419Z 63 PC: 163ab | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:18:00.870160832Z 66 PC: 163a0 | Move file pointer
2018-12-17T22:18:00.872420537Z 63 PC: 163ab | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:18:00.8795606Z 66 PC: 163a0 | Move file pointer
2018-12-17T22:18:00.881231922Z 63 PC: 163ab | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:18:00.884352141Z 63 PC: 16412 | Read file or device (Read 2641 bytes on handle 5)
2018-12-17T22:18:00.889544467Z 62 PC: 16312 | Close file
2018-12-17T22:18:00.891027075Z 48 PC: 14bc9 | Get DOS version
2018-12-17T22:18:00.892722617Z 2 PC: 149ad | Character output (Char = '8d')
2018-12-17T22:18:00.894334242Z 2 PC: 149ad | Character output (Char = 'a5')
2018-12-17T22:18:00.895849649Z 2 PC: 149ad | Character output (Char = 'a2')
2018-12-17T22:18:00.898052744Z 2 PC: 149ad | Character output (Char = 'a5')
2018-12-17T22:18:00.899528935Z 2 PC: 149ad | Character output (Char = 'e0')
2018-12-17T22:18:00.900976377Z 2 PC: 149ad | Character output (Char = 'ad')
2018-12-17T22:18:00.903105982Z 2 PC: 149ad | Character output (Char = 'a0')
2018-12-17T22:18:00.905012295Z 2 PC: 149ad | Character output (Char = 'ef')
2018-12-17T22:18:00.906961205Z 2 PC: 149ad | Character output (Char = '20')
2018-12-17T22:18:00.909050414Z 2 PC: 149ad | Character output (Char = 'a2')
2018-12-17T22:18:00.910915321Z 2 PC: 149ad | Character output (Char = 'a5')
2018-12-17T22:18:00.912779524Z 2 PC: 149ad | Character output (Char = 'e0')
2018-12-17T22:18:00.914964825Z 2 PC: 149ad | Character output (Char = 'e1')
2018-12-17T22:18:00.917053345Z 2 PC: 149ad | Character output (Char = 'a8')
2018-12-17T22:18:00.919299525Z 2 PC: 149ad | Character output (Char = 'ef')
2018-12-17T22:18:00.921674202Z 2 PC: 149ad | Character output (Char = '20')
2018-12-17T22:18:00.923928424Z 2 PC: 149ad | Character output (Char = '4d')
2018-12-17T22:18:00.92649113Z 2 PC: 149ad | Character output (Char = '53')
2018-12-17T22:18:00.929477025Z 2 PC: 149ad | Character output (Char = '2d')
2018-12-17T22:18:00.933115676Z 2 PC: 149ad | Character output (Char = '44')
2018-12-17T22:18:00.935848825Z 2 PC: 149ad | Character output (Char = '4f')
2018-12-17T22:18:00.937938948Z 2 PC: 149ad | Character output (Char = '53')
2018-12-17T22:18:00.940897896Z 2 PC: 149ad | Character output (Char = '0d')
2018-12-17T22:18:00.943614321Z 2 PC: 149ad | Character output (Char = '0a')