Sample viewer

vx.netlux.org/Trojan.DOS.KillHDD.k

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:30.966895672Z 53 PC: 1374a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:30.96874813Z 53 PC: 1374a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:35:30.970664535Z 53 PC: 1374a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:30.972654219Z 53 PC: 1374a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:30.975089761Z 53 PC: 1374a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:30.976917713Z 53 PC: 1374a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:30.978962127Z 53 PC: 1374a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:35:30.981208244Z 53 PC: 1374a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:35:30.982737199Z 53 PC: 1374a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:35:30.984048646Z 53 PC: 1374a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:35:30.985356456Z 53 PC: 1374a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:35:30.986875295Z 53 PC: 1374a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:35:30.988022819Z 53 PC: 1374a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:35:30.989226734Z 53 PC: 1374a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:35:30.991777324Z 53 PC: 1374a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:35:30.993005784Z 53 PC: 1374a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:35:30.9946775Z 53 PC: 1374a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:35:30.996644553Z 53 PC: 1374a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:30.997785348Z 53 PC: 1374a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:35:30.998925931Z 37 PC: 1375f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:31.000874265Z 37 PC: 13767 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:31.002088206Z 37 PC: 1376f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:31.003237716Z 37 PC: 13777 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:31.005545903Z 68 PC: 14406 | I/O control for devices (Set for = '2����0�ઊ�����S��ERV�')
2018-12-17T22:35:31.141621698Z 37 PC: 13001 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:31.142997887Z 53 PC: 1358f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:35:31.144588166Z 37 PC: 135ab | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:35:31.145928026Z 44 PC: 1453d | Get time 0x1453d: mov word ptr [0x3e], cx
0x14541: mov word ptr [0x40], dx
0x14545: retf
0x14546: call 0x1458d
0x14549: jb 0x1455a
0x1454b: mov cx, word ptr es:[di + 4]
0x1454f: cmp cx, 1
0x14552: je 0x1455a
0x14554: xor bx, bx
0x14556: push cs
0x14557: call 0x240ce
0x1455a: retf 4
0x1455d: call 0x1458d
0x14560: jb 0x14575
0x14562: mov ax, cx
0x14564: mov dx, bx
0x14566: mov cx, word ptr es:[di + 4]
0x1456a: cmp cx, 1
0x1456d: je 0x14575
0x1456f: xor bx, bx
2018-12-17T22:35:31.148108996Z 48 PC: 13584 | Get DOS version
2018-12-17T22:35:31.149608326Z 48 PC: 1401c | Get DOS version
2018-12-17T22:35:31.150807918Z 48 PC: 1401c | Get DOS version
2018-12-17T22:35:31.15184129Z 48 PC: 1401c | Get DOS version
2018-12-17T22:35:31.153214261Z 61 PC: 13e5a | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:31.158905487Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.161671198Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.16442989Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.168321421Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.181446587Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.183270734Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.185800137Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.187619841Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.196280593Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.198664954Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.200267218Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.202041902Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.211037522Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.21274547Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.214352114Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.216812533Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.224677948Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.226126653Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.227807515Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.230435018Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.23921786Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.240831182Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.243386514Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.249930158Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.257861839Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.260047103Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.262059729Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.264278623Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.286135691Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.28731176Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.288888596Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.291770752Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.299488839Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.300885798Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.302797649Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.304392024Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.312008549Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.313894622Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.315321596Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.316690558Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.325454979Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.327138819Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.328545379Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.330184419Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.338462485Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.34001184Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.341607266Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.343916867Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.351551707Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.352992716Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.355426956Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.356937689Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.364871035Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.366896636Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.368183137Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.369715433Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.37800873Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.379610752Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.38100937Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.383519905Z 64 PC: 13f2d | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:35:31.391993906Z 66 PC: 145a7 | Move file pointer
2018-12-17T22:35:31.393355287Z 66 PC: 145b5 | Move file pointer
2018-12-17T22:35:31.395200376Z 66 PC: 145c3 | Move file pointer
2018-12-17T22:35:31.396668871Z 62 PC: 13eaa | Close file
2018-12-17T22:35:31.405588705Z 65 PC: 13fa3 | Delete file (Filename = 'A:\TEST.EXE')
2018-12-17T22:35:31.827437418Z 61 PC: 143ea | Open file (Filename = 'A:\INSTALL.DAT')
2018-12-17T22:35:31.835699404Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:35:31.837239088Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:35:31.839374512Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:35:31.840932058Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:31.842274048Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:31.844138367Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:31.845445463Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:35:31.846706014Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:35:31.848224843Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:35:31.849667927Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:35:31.850938056Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:35:31.852475101Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:35:31.853874843Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:35:31.855077143Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:35:31.856495997Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:35:31.858489613Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:35:31.859722531Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:35:31.861487866Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:35:31.86421788Z 37 PC: 138a1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:35:31.865362088Z 76 PC: 138e0 | Terminate with return code (Return code = '0')