Sample viewer

vx.netlux.org/Trojan.DOS.Ugly

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:33.102202358Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:53:33.104350242Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:33.106287642Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:53:33.107936469Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:53:33.113177674Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:53:33.11517703Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:33.117337839Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.135647061Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.150081706Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.162724625Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.175742808Z 64 PC: 12c21 | Write file or device (Write 30 bytes on handle 2)
2018-12-17T22:53:33.180405537Z 37 PC: 12bef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:33.181793053Z 37 PC: 12bfa | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:53:33.18303699Z 37 PC: 12c05 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:53:33.185632866Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:53:33.198494626Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.211808104Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.2251732Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.237888254Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.250340595Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:53:33.2638602Z 74 PC: 12b19 | Reallocate memory