Sample viewer

vx.netlux.org/Trojan.DOS.Hoodeasy

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:22.741407261Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:54:22.743679759Z 53 PC: 12bbe | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:22.745435838Z 53 PC: 12bcb | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:54:22.751366768Z 53 PC: 12bd8 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:54:22.754451192Z 53 PC: 12be5 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:54:22.756428256Z 37 PC: 12bf9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:22.758491382Z 74 PC: 12adb | Reallocate memory
2018-12-17T22:54:22.760667168Z 68 PC: 1302e | I/O control for devices (Set for = '')
2018-12-17T22:54:22.763885874Z 74 PC: 1853a | Reallocate memory
2018-12-17T22:54:22.766526154Z 68 PC: 1302e | I/O control for devices (Set for = 'ument Required parameter missing Unrecognized switch %A bad UMB number has been specified  %1.%2 to 1.09 %1.%2 to 1.0 average compression ratio Overwrite %1 (Yes/No/All)?YNA ')
2018-12-17T22:54:22.771347841Z 28 PC: 12e36 | Get allocation info for specified drive
2018-12-17T22:54:22.791959988Z 28 PC: 12e36 | Get allocation info for specified drive