Sample viewer

vx.netlux.org/Trojan.DOS.Erase1Asm.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:10.498316107Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:33:10.499959228Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:33:10.501130412Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:33:10.502238998Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:33:10.504279814Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:33:10.505374827Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:10.506449721Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:33:10.507470284Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:33:10.509360154Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:33:10.510825014Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:33:10.512698316Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:33:10.514630903Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:33:10.516483565Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:33:10.517846476Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:33:10.519798057Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:33:10.521274705Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:33:10.522759876Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:33:10.524349217Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:33:10.525418904Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:33:10.526520818Z 37 PC: 12b1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:33:10.528113246Z 37 PC: 12b27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:33:10.529399886Z 37 PC: 12b2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:10.530638322Z 37 PC: 12b37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:33:10.533381894Z 68 PC: 13151 | I/O control for devices (Set for = '�&�>�t�)�h�&�>�t���-&�n$P3�&���t&�&�>�t��&�')
2018-12-17T22:33:10.535808654Z 61 PC: 12fcd | Open file (Filename = '1.asm')
2018-12-17T22:33:10.542811785Z 64 PC: 12f28 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:33:10.545014191Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:33:10.546184134Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:33:10.547326439Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:33:10.548676333Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:33:10.550258459Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:33:10.551197336Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:10.552712202Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:33:10.55393797Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:33:10.555015373Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:33:10.556698948Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:33:10.558055612Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:33:10.559123135Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:33:10.561147909Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:33:10.562150901Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:33:10.563041997Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:33:10.563942034Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:33:10.565429941Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:33:10.566476705Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:33:10.567474474Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:33:10.569579864Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.571662906Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.573687114Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.576322126Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.578592824Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.580621218Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.583942428Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.58600243Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.587973411Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.590844675Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.592948291Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.595241626Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.5980694Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.60039982Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.602817661Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.605772286Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.608007016Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.610258808Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.612845519Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.614787932Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.616543057Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.619795508Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.622117669Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.624422372Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.626997047Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.628846142Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.630609357Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.632654525Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.636589361Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.640169072Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.642557546Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.645022854Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.64718754Z 6 PC: 12ce8 | Direct console I/O
2018-12-17T22:33:10.651096822Z 76 PC: 12ca0 | Terminate with return code (Return code = '2')