Sample viewer

vx.netlux.org/Trojan.DOS.KillAutoexec

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:38.325742525Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:41:38.327946163Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:38.329319002Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:41:38.330804201Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:41:38.332237433Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:41:38.334501816Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:38.335982547Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:41:38.338049309Z 68 PC: 14234 | I/O control for devices (Set for = '��')
2018-12-17T22:41:38.341252525Z 68 PC: 14234 | I/O control for devices (Set for = '')
2018-12-17T22:41:38.343852128Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:38.345430142Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:38.347989298Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:38.349597899Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:38.351145787Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:38.356944287Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:38.358394882Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:38.35977264Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:38.362089982Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:38.364555262Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:38.366420866Z 53 PC: 12d5c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:38.370073146Z 53 PC: 12d6c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:38.372648634Z 53 PC: 12d79 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:38.374476777Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:38.375826312Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:38.377911268Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:38.379582136Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:38.381195677Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:38.383717393Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:38.387870674Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:38.389965117Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:38.392083245Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:38.393806752Z 37 PC: 12e80 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:38.39548237Z 37 PC: 12e8b | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:38.398191839Z 37 PC: 12e95 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:38.401314384Z 25 PC: 140a6 | Get default drive
2018-12-17T22:41:38.402607833Z 71 PC: 1415a | Get current directory
2018-12-17T22:41:38.406070947Z 47 PC: 140f6 | Get disk transfer address
2018-12-17T22:41:38.407954716Z 26 PC: 140ff | Set disk transfer address
2018-12-17T22:41:38.409270357Z 78 PC: 14109 | Find first file
2018-12-17T22:41:38.416504794Z 26 PC: 14111 | Set disk transfer address
2018-12-17T22:41:38.419168687Z 47 PC: 140f6 | Get disk transfer address
2018-12-17T22:41:38.420480872Z 26 PC: 140ff | Set disk transfer address
2018-12-17T22:41:38.421830787Z 78 PC: 14109 | Find first file
2018-12-17T22:41:38.432652954Z 26 PC: 14111 | Set disk transfer address
2018-12-17T22:41:38.434435862Z 67 PC: 140c5 | Get or set file attributes
2018-12-17T22:41:38.440906195Z 60 PC: 14374 | Create or truncate file
2018-12-17T22:41:38.460002051Z 68 PC: 14234 | I/O control for devices (Set for = '�؛.�')
2018-12-17T22:41:38.463320073Z 64 PC: 14d12 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:41:38.467985646Z 62 PC: 140da | Close file
2018-12-17T22:41:38.482392455Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:41:38.484175223Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:41:38.485666915Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:41:38.488415076Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:41:38.489725137Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:41:38.49098338Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:41:38.492856108Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:41:38.494153725Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:41:38.495354269Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:41:38.496837665Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:41:38.498909978Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:41:38.50005049Z 37 PC: 12f16 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:41:38.502048072Z 37 PC: 12f1f | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:41:38.506166677Z 62 PC: 140da | Close file
2018-12-17T22:41:38.508415611Z 62 PC: 140da | Close file
2018-12-17T22:41:38.510596006Z 62 PC: 140da | Close file
2018-12-17T22:41:38.515998042Z 62 PC: 140da | Close file
2018-12-17T22:41:38.518092086Z 62 PC: 140da | Close file
2018-12-17T22:41:38.52028244Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:38.522415546Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:41:38.524136007Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:41:38.525737084Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:41:38.528069545Z 76 PC: 12b9c | Terminate with return code (Return code = '0')