Sample viewer

vx.netlux.org/Trojan.DOS.EraseHD

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:25.887227983Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:45:25.888959958Z 53 PC: 12b75 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:25.890637035Z 53 PC: 12b82 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:45:25.892287638Z 53 PC: 12b8f | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:45:25.894255739Z 53 PC: 12b9c | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:45:25.895915882Z 37 PC: 12bb0 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:25.897609668Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:45:25.900743034Z 74 PC: 13337 | Reallocate memory
2018-12-17T22:45:26.337599193Z 37 PC: 12bbc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:26.339046237Z 37 PC: 12bc7 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:45:26.340808565Z 37 PC: 12bd2 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:45:26.342904062Z 37 PC: 12bdd | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:45:26.344209583Z 76 PC: 12b65 | Terminate with return code (Return code = '0')