Sample viewer

vx.netlux.org/Trojan.DOS.CD19.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:50.564757526Z 98 PC: 12a44 | Get current PSP
2018-12-17T22:55:50.56635713Z 60 PC: 12a83 | Create or truncate file
2018-12-17T22:55:50.583536355Z 64 PC: 12a8e | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:55:50.587844115Z 78 PC: 12a9c | Find first file
2018-12-17T22:55:50.595294533Z 74 PC: 12ae4 | Reallocate memory
2018-12-17T22:55:50.597410814Z 75 PC: 12b0a | Execute program
2018-12-17T22:55:50.618755863Z 80 PC: 18029 | Set current PSP
2018-12-17T22:55:50.620377682Z 48 PC: 1802e | Get DOS version
2018-12-17T22:55:50.622286277Z 99 PC: 1e810 | Get DBCS lead byte table pointer
2018-12-17T22:55:50.625218429Z 101 PC: 180b4 | Get extended country info
2018-12-17T22:55:50.627056347Z 99 PC: 180ba | Get DBCS lead byte table pointer
2018-12-17T22:55:50.629140115Z 74 PC: 1811c | Reallocate memory
2018-12-17T22:55:50.630570802Z 25 PC: 18153 | Get default drive
2018-12-17T22:55:50.631636809Z 37 PC: 17c13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:55:50.632883944Z 37 PC: 17c1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:50.633941313Z 37 PC: 17c21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:50.638178425Z 74 PC: 16dbc | Reallocate memory
2018-12-17T22:55:50.640756128Z 72 PC: 16dfd | Allocate memory
2018-12-17T22:55:50.642324052Z 72 PC: 16e35 | Allocate memory
2018-12-17T22:55:50.643849673Z 72 PC: 16e3d | Allocate memory