Sample viewer

vx.netlux.org/Trojan.DOS.DelAll.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:00.055997564Z 53 PC: 1366a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:00.058332501Z 53 PC: 1366a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:00.059792721Z 53 PC: 1366a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:00.060991135Z 53 PC: 1366a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:00.063130496Z 53 PC: 1366a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:00.064698215Z 53 PC: 1366a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:00.066334146Z 53 PC: 1366a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:00.068214575Z 53 PC: 1366a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:00.07024585Z 53 PC: 1366a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:00.071912627Z 53 PC: 1366a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:00.07358096Z 53 PC: 1366a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:00.078705775Z 53 PC: 1366a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:00.080184297Z 53 PC: 1366a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:00.081650495Z 53 PC: 1366a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:00.084043094Z 53 PC: 1366a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:00.085499105Z 53 PC: 1366a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:00.086707074Z 53 PC: 1366a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:00.088208782Z 53 PC: 1366a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:00.089259724Z 53 PC: 1366a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:00.090155179Z 37 PC: 1367f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:00.091727413Z 37 PC: 13687 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:00.092620997Z 37 PC: 1368f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:00.093734535Z 37 PC: 13697 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:00.09620435Z 68 PC: 13def | I/O control for devices (Set for = '�3���p')
2018-12-17T22:20:00.230918633Z 64 PC: 13a88 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:20:00.232762293Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:20:00.235182266Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:20:00.236854946Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:20:00.238411054Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:00.240161278Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:20:00.241747337Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:00.243126363Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:20:00.244681666Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:20:00.24707087Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:20:00.248224902Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:20:00.249385363Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:20:00.25117428Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:20:00.252285517Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:20:00.253511432Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:20:00.254972912Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:20:00.256096438Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:20:00.257060552Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:20:00.259124512Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:20:00.26049226Z 37 PC: 137c1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:20:00.262784783Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.278185899Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.280601265Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.283056573Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.302748465Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.305170917Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.307551651Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.310277676Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.31234383Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.314342063Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.317244466Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.319932416Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.322700063Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.325627289Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.32872992Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.331613713Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.334342558Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.337162825Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.343123169Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.345684885Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.347673576Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.350426327Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.352889712Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.354822297Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.356676961Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.358998753Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.360873465Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.362695747Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.365202416Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.36715852Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.369245194Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.371640382Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.373510578Z 6 PC: 13848 | Direct console I/O
2018-12-17T22:20:00.377126884Z 76 PC: 13800 | Terminate with return code (Return code = '200')