Sample viewer

vx.netlux.org/Trojan.DOS.KillMBR.e

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:15.840477841Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:15.845727312Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:15.846989319Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:15.848643949Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:15.851781039Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:15.853190097Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:15.854749263Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:15.85619953Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:15.865986821Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:15.867675541Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:15.869307024Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:15.873124489Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:15.87607631Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:15.877589887Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:15.879596635Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:15.881590246Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:15.883330915Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:15.886475585Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:15.887859427Z 53 PC: 12b1a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:15.889081573Z 37 PC: 12b2f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:15.890508481Z 37 PC: 12b37 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:15.891967376Z 37 PC: 12b3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:15.893151691Z 37 PC: 12b47 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:15.895560906Z 68 PC: 12fa2 | I/O control for devices (Set for = '!&�M���3�������u���wA�f#t ��sQ��hA� ���')
2018-12-17T22:43:15.898178725Z 53 PC: 12a9a | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:43:15.899444887Z 37 PC: 12ab6 | Set interrupt vector (Interrupt = '102' AKA 'Get or set code page')
2018-12-17T22:43:16.242086195Z 64 PC: 12f38 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:43:16.244520705Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:16.246019847Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:43:16.24750801Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:43:16.250159775Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:16.251618618Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:43:16.25308435Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:43:16.254962696Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:43:16.256400027Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:43:16.257725103Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:43:16.259510963Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:43:16.26062285Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:43:16.261675852Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:43:16.263182375Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:43:16.264652107Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:43:16.266028012Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:43:16.267884087Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:43:16.269187689Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:43:16.27058716Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:43:16.27254933Z 37 PC: 12c71 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:43:16.273969089Z 76 PC: 12cb0 | Terminate with return code (Return code = '0')