Sample viewer

vx.netlux.org/Trojan.DOS.Zhek

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:42.851111127Z 48 PC: 13161 | Get DOS version
2018-12-17T22:54:42.853815615Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:54:42.855400152Z 74 PC: 12d49 | Reallocate memory
2018-12-17T22:54:42.856912466Z 74 PC: 12d4d | Reallocate memory
2018-12-17T22:54:42.868197068Z 37 PC: 15ce3 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')