Sample viewer

vx.netlux.org/Trojan.DOS.CMOSKiller.e

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:49.813704981Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:49.821581681Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:49.822759617Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:49.823844221Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:49.825838206Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:49.827292901Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:49.828735452Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:49.831027884Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:49.832778792Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:49.83419199Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:49.835864817Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:49.837796406Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:49.838934683Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:49.840242057Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:49.842088625Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:49.843576649Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:49.844815801Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:49.84663506Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:49.848148259Z 53 PC: 12b02 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:49.849683252Z 37 PC: 12b17 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:49.852160947Z 37 PC: 12b1f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:49.853708833Z 37 PC: 12b27 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:49.855140449Z 37 PC: 12b2f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:49.858219593Z 68 PC: 12e9f | I/O control for devices (Set for = '')
2018-12-17T21:53:49.860196242Z 64 PC: 12fa2 | Write file or device (Write 42 bytes on handle 1)
2018-12-17T21:53:49.974918075Z 64 PC: 12fa2 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T21:53:49.977966672Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:49.979256058Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T21:53:49.980436154Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T21:53:49.981793821Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:49.983229923Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:53:49.984337843Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:53:49.986027598Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T21:53:49.987187779Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T21:53:49.988380196Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T21:53:49.989921669Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T21:53:49.991043837Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T21:53:49.992051906Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T21:53:49.993279185Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T21:53:49.995127358Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T21:53:49.996394981Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T21:53:49.998289471Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T21:53:50.001739732Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T21:53:50.003641657Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T21:53:50.00489272Z 37 PC: 12c16 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T21:53:50.006526155Z 76 PC: 12c55 | Terminate with return code (Return code = '0')