Sample viewer

vx.netlux.org/Trojan.DOS.Decimation

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:18.81870576Z 48 PC: 12a4c | Get DOS version
2018-12-17T21:57:18.821305565Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:18.822778109Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:57:18.8242045Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:57:18.825642495Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:57:18.827988574Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:18.82931389Z 74 PC: 12af4 | Reallocate memory
2018-12-17T21:57:18.831421494Z 68 PC: 135d6 | I/O control for devices (Set for = '�"')
2018-12-17T21:57:18.834401688Z 68 PC: 135d6 | I/O control for devices (Set for = '�"')
2018-12-17T21:57:18.836429886Z 28 PC: 13560 | Get allocation info for specified drive
2018-12-17T21:57:20.506615909Z 28 PC: 13560 | Get allocation info for specified drive
2018-12-17T21:57:20.510973663Z 64 PC: 13c18 | Write file or device (Write 15 bytes on handle 1)
2018-12-17T21:57:20.515228924Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:57:20.516818298Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:57:20.519611443Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:57:20.521579143Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:57:20.523540517Z 76 PC: 12b9c | Terminate with return code (Return code = '15')