Sample viewer

vx.netlux.org/Trojan.DOS.EraseHDD.i

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:08.377396129Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:18:08.384210294Z 41 PC: 94fae | Parse filename
2018-12-17T22:18:08.389797491Z 41 PC: 9502f | Parse filename
2018-12-17T22:18:08.395737034Z 41 PC: 9504c | Parse filename
2018-12-17T22:18:08.398532201Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:18:08.400468657Z 71 PC: 986f3 | Get current directory
2018-12-17T22:18:08.403504082Z 78 PC: 986fe | Find first file
2018-12-17T22:18:08.413005829Z 71 PC: 986f3 | Get current directory
2018-12-17T22:18:08.415914392Z 78 PC: 986fe | Find first file
2018-12-17T22:18:08.427513072Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T22:18:08.432954279Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:18:08.434507942Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:18:08.435709422Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:08.43709114Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.439126452Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.440669605Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.442191634Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.443913818Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.44532543Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.446641019Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.448341737Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.450462508Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.451975609Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.453389256Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.455474224Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.456952346Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.45843622Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.460381071Z 62 PC: 122ab | Close file
2018-12-17T22:18:08.462040847Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:18:08.463464711Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:18:08.473788111Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:18:08.477996541Z 25 PC: 94e62 | Get default drive
2018-12-17T22:18:08.479874963Z 71 PC: 970dd | Get current directory
2018-12-17T22:18:08.486788675Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:18:08.489763899Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:18:08.491705146Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:18:08.493608256Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:18:08.495179226Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:18:23.424398031Z 0 PC: 0 | Program terminate
2018-12-17T22:18:24.783195634Z 0 PC: 0 | Program terminate
2018-12-17T22:18:24.885840299Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:18:24.892468304Z 41 PC: 94fae | Parse filename
2018-12-17T22:18:24.894968947Z 41 PC: 9502f | Parse filename
2018-12-17T22:18:24.897874395Z 41 PC: 9504c | Parse filename
2018-12-17T22:18:24.902266515Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:18:24.904111448Z 71 PC: 986f3 | Get current directory
2018-12-17T22:18:24.912009373Z 78 PC: 986fe | Find first file
2018-12-17T22:18:24.921357365Z 71 PC: 9856c | Get current directory
2018-12-17T22:18:24.924891576Z 73 PC: 97c09 | Release memory
2018-12-17T22:18:24.926445305Z 75 PC: 11821 | Execute program
2018-12-17T22:18:24.940768906Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:18:24.946484199Z 76 PC: 12a4b | Terminate with return code (Return code = '36')