Sample viewer

vx.netlux.org/Trojan.DOS.SaveName

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:05.174741114Z 32 PC: 13990 | Reserved
2018-12-17T22:50:05.17683783Z 67 PC: 1399e | Get or set file attributes
2018-12-17T22:50:05.183010645Z 60 PC: 139a6 | Create or truncate file
2018-12-17T22:50:05.8459064Z 62 PC: 139ad | Close file
2018-12-17T22:50:05.848558487Z 88 PC: 139b2 | case 0xGet or set allocation strateg:
2018-12-17T22:50:05.849879881Z 48 PC: 139b7 | Get DOS version
2018-12-17T22:50:05.851405709Z 88 PC: 139c5 | case 0xGet or set allocation strateg:
2018-12-17T22:50:05.853613901Z 88 PC: 139ca | case 0xGet or set allocation strateg:
2018-12-17T22:50:05.854788589Z 88 PC: 139d4 | case 0xGet or set allocation strateg:
2018-12-17T22:50:05.856026937Z 72 PC: 13a6a | Allocate memory
2018-12-17T22:50:05.857849832Z 88 PC: 139dd | case 0xGet or set allocation strateg:
2018-12-17T22:50:05.859430932Z 88 PC: 139e1 | case 0xGet or set allocation strateg:
2018-12-17T22:50:05.860686208Z 74 PC: 139f6 | Reallocate memory
2018-12-17T22:50:05.863239749Z 72 PC: 13a6a | Allocate memory
2018-12-17T22:50:05.864936478Z 81 PC: 13a2c | Get current PSP
2018-12-17T22:50:05.865744286Z 48 PC: 12a54 | Get DOS version
2018-12-17T22:50:05.866999595Z 74 PC: 12ad3 | Reallocate memory
2018-12-17T22:50:05.869555071Z 53 PC: 12b51 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:05.870735064Z 37 PC: 12b63 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:05.871890355Z 68 PC: 12bf3 | I/O control for devices (Set for = '/[r��׹��2����E�$� �!�E�')
2018-12-17T22:50:05.873662402Z 68 PC: 12bf3 | I/O control for devices
2018-12-17T22:50:05.874913181Z 68 PC: 12bf3 | I/O control for devices
2018-12-17T22:50:05.876219214Z 68 PC: 12bf3 | I/O control for devices
2018-12-17T22:50:05.878193999Z 68 PC: 12bf3 | I/O control for devices
2018-12-17T22:50:05.880516695Z 74 PC: 1317e | Reallocate memory
2018-12-17T22:50:05.882548324Z 48 PC: 1327d | Get DOS version
2018-12-17T22:50:05.88440357Z 72 PC: 13433 | Allocate memory
2018-12-17T22:50:05.886051023Z 41 PC: 134a8 | Parse filename
2018-12-17T22:50:05.887318456Z 41 PC: 134b0 | Parse filename
2018-12-17T22:50:05.897791438Z 75 PC: 1347d | Execute program
2018-12-17T22:50:05.904289003Z 37 PC: 12cc3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:50:05.905377228Z 76 PC: 12ca8 | Terminate with return code (Return code = '2')