Sample viewer

vx.netlux.org/Trojan.DOS.DelAll.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:10.960338068Z 48 PC: 12b6e | Get DOS version
2018-12-17T22:24:10.962462095Z 74 PC: 12bcd | Reallocate memory
2018-12-17T22:24:10.964376084Z 48 PC: 12c32 | Get DOS version
2018-12-17T22:24:10.965496595Z 53 PC: 12c3a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:10.967369272Z 68 PC: 12cda | I/O control for devices (Set for = '')
2018-12-17T22:24:10.969015838Z 68 PC: 12cda | I/O control for devices
2018-12-17T22:24:10.970557278Z 68 PC: 12cda | I/O control for devices
2018-12-17T22:24:10.980517192Z 68 PC: 12cda | I/O control for devices
2018-12-17T22:24:10.982279216Z 68 PC: 12cda | I/O control for devices
2018-12-17T22:24:10.984146176Z 53 PC: 17026 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:10.985508975Z 37 PC: 1703c | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:10.987193252Z 53 PC: 155b6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:10.988519912Z 53 PC: 155c3 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:24:10.989841938Z 53 PC: 155d0 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:10.991564874Z 37 PC: 155e2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:10.992808482Z 37 PC: 155ea | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:24:10.994053465Z 37 PC: 157d0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:10.999828096Z 74 PC: 1642b | Reallocate memory
2018-12-17T22:24:11.001954404Z 74 PC: 1642b | Reallocate memory
2018-12-17T22:24:11.007404785Z 68 PC: 14d62 | I/O control for devices
2018-12-17T22:24:11.022650273Z 68 PC: 14d62 | I/O control for devices
2018-12-17T22:24:11.024386446Z 51 PC: 14d7f | Get or set Ctrl-Break
2018-12-17T22:24:11.025337691Z 51 PC: 14d8b | Get or set Ctrl-Break
2018-12-17T22:24:11.035497082Z 54 PC: 1542e | Get free disk space
2018-12-17T22:24:11.081249395Z 61 PC: 15184 | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:24:11.094526324Z 68 PC: 150d2 | I/O control for devices (Set for = '')
2018-12-17T22:24:11.098794632Z 64 PC: 15357 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:24:11.76770305Z 64 PC: 15357 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:24:11.781573796Z 66 PC: 14ebb | Move file pointer
2018-12-17T22:24:11.783659909Z 62 PC: 14f88 | Close file
2018-12-17T22:24:11.797171228Z 51 PC: 14d96 | Get or set Ctrl-Break
2018-12-17T22:24:11.798277791Z 37 PC: 15628 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:11.799602124Z 37 PC: 15632 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:24:11.80135455Z 37 PC: 1563c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:11.803486386Z 37 PC: 12da0 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:11.804825267Z 76 PC: 12d86 | Terminate with return code (Return code = '0')