Sample viewer

vx.netlux.org/Trojan.DOS.EraseSystem.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:56.032619204Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:46:56.038406953Z 53 PC: 12bf2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:56.040146083Z 53 PC: 12bff | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:46:56.041849977Z 53 PC: 12c0c | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:46:56.044574776Z 53 PC: 12c19 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:46:56.046120496Z 37 PC: 12c2d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:56.047731847Z 74 PC: 12af7 | Reallocate memory
2018-12-17T22:46:56.058699235Z 68 PC: 12fac | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:46:56.06174311Z 68 PC: 12fac | I/O control for devices (Set for = '')
2018-12-17T22:46:56.066469549Z 68 PC: 12fac | I/O control for devices (Set for = '')
2018-12-17T22:46:56.070800169Z 67 PC: 13413 | Get or set file attributes
2018-12-17T22:46:56.07800076Z 61 PC: 13858 | Open file (Filename = 'c:\command.com')
2018-12-17T22:46:56.086221312Z 68 PC: 13178 | I/O control for devices (Set for = 'Copyright 1991 Borland Intl.')
2018-12-17T22:46:56.088301969Z 64 PC: 136df | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:46:56.43148965Z 66 PC: 12fd0 | Move file pointer
2018-12-17T22:46:56.435462224Z 64 PC: 13b56 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:46:56.440531962Z 62 PC: 1344e | Close file
2018-12-17T22:46:56.452208852Z 67 PC: 13413 | Get or set file attributes
2018-12-17T22:46:56.466438891Z 67 PC: 13413 | Get or set file attributes
2018-12-17T22:46:56.474370306Z 60 PC: 136c5 | Create or truncate file
2018-12-17T22:46:56.489191268Z 66 PC: 12fd0 | Move file pointer
2018-12-17T22:46:56.493002809Z 64 PC: 13b56 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:46:56.498091644Z 62 PC: 1344e | Close file
2018-12-17T22:46:56.508569539Z 67 PC: 13413 | Get or set file attributes
2018-12-17T22:46:56.515707666Z 61 PC: 13858 | Open file (Filename = 'c:\windows\win.com')
2018-12-17T22:46:56.527067556Z 68 PC: 13178 | I/O control for devices (Set for = 'Copyright 1991 Borland Intl.')
2018-12-17T22:46:56.530493411Z 64 PC: 136df | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:46:56.538919148Z 66 PC: 12fd0 | Move file pointer
2018-12-17T22:46:56.543650457Z 64 PC: 13b56 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:46:56.548721248Z 62 PC: 1344e | Close file
2018-12-17T22:46:56.559817743Z 67 PC: 13413 | Get or set file attributes
2018-12-17T22:46:56.566708808Z 61 PC: 13858 | Open file (Filename = 'c:\autoexec.bat')
2018-12-17T22:46:56.574372587Z 68 PC: 13178 | I/O control for devices (Set for = 'Copyright 1991 Borland Intl.')
2018-12-17T22:46:56.57714418Z 64 PC: 136df | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:46:56.586593419Z 66 PC: 12fd0 | Move file pointer
2018-12-17T22:46:56.590375908Z 64 PC: 13b56 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:46:56.596015436Z 62 PC: 1344e | Close file
2018-12-17T22:46:56.606070305Z 67 PC: 13413 | Get or set file attributes
2018-12-17T22:46:56.613370685Z 61 PC: 13858 | Open file (Filename = 'c:\config.sys')
2018-12-17T22:46:56.621385393Z 68 PC: 13178 | I/O control for devices (Set for = 'Copyright 1991 Borland Intl.')
2018-12-17T22:46:56.623379094Z 64 PC: 136df | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:46:56.631158389Z 66 PC: 12fd0 | Move file pointer
2018-12-17T22:46:56.635494562Z 64 PC: 13b56 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:46:56.640783959Z 62 PC: 1344e | Close file
2018-12-17T22:46:56.65222161Z 37 PC: 12c39 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:56.65451008Z 37 PC: 12c44 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:46:56.6559405Z 37 PC: 12c4f | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:46:56.65766627Z 37 PC: 12c5a | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:46:56.65949901Z 76 PC: 12be3 | Terminate with return code (Return code = '212')