Sample viewer

vx.netlux.org/Trojan.DOS.Lala

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:42.94972784Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:52:42.952062716Z 41 PC: 12aba | Parse filename
2018-12-17T22:52:42.954240928Z 41 PC: 12ac2 | Parse filename
2018-12-17T22:52:42.956129155Z 75 PC: 12add | Execute program
2018-12-17T22:52:42.982005724Z 80 PC: 14a19 | Set current PSP
2018-12-17T22:52:42.98449003Z 48 PC: 14a1e | Get DOS version
2018-12-17T22:52:42.987412761Z 99 PC: 1b200 | Get DBCS lead byte table pointer
2018-12-17T22:52:42.991413727Z 101 PC: 14aa4 | Get extended country info
2018-12-17T22:52:42.994126753Z 99 PC: 14aaa | Get DBCS lead byte table pointer
2018-12-17T22:52:42.998807906Z 74 PC: 14b0c | Reallocate memory
2018-12-17T22:52:43.00071569Z 25 PC: 14b43 | Get default drive
2018-12-17T22:52:43.003667996Z 37 PC: 14603 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:52:43.005358822Z 37 PC: 1460a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:43.006807935Z 37 PC: 14611 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:43.01206545Z 74 PC: 137ac | Reallocate memory
2018-12-17T22:52:43.014029039Z 72 PC: 137ed | Allocate memory
2018-12-17T22:52:43.015925111Z 72 PC: 13825 | Allocate memory
2018-12-17T22:52:43.017924467Z 72 PC: 1382d | Allocate memory