Sample viewer

vx.netlux.org/Trojan.DOS.Erase26.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:31.070905896Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:21:31.0730966Z 53 PC: 12be0 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:31.074206056Z 53 PC: 12bed | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:21:31.075356793Z 53 PC: 12bfa | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:21:31.077554932Z 53 PC: 12c07 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:21:31.078779611Z 37 PC: 12c1b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:31.079965991Z 74 PC: 12af7 | Reallocate memory
2018-12-17T22:21:31.082655055Z 68 PC: 12ffa | I/O control for devices (Set for = 'L')
2018-12-17T22:21:31.084459127Z 68 PC: 12ffa | I/O control for devices (Set for = '')
2018-12-17T22:21:31.087957515Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.800418296Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.803681871Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.806484762Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.813205004Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.815539117Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.818094072Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.821401704Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.824093845Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.826320815Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.828972258Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.832017161Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.834130673Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.836202141Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.839398778Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.841539929Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.843640536Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.846090364Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.848182103Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.85025221Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.853025543Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.855085393Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.857128669Z 28 PC: 12f60 | Get allocation info for specified drive
2018-12-17T22:21:31.864813275Z 37 PC: 12c27 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:31.866433029Z 37 PC: 12c32 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:21:31.868006116Z 37 PC: 12c3d | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:21:31.875571203Z 37 PC: 12c48 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:21:31.87718102Z 76 PC: 12bcb | Terminate with return code (Return code = '255')