Sample viewer

vx.netlux.org/Trojan.DOS.FoxPro

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:59.330348225Z 48 PC: 13161 | Get DOS version
2018-12-17T22:55:59.333280609Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:55:59.335215873Z 74 PC: 12d49 | Reallocate memory
2018-12-17T22:55:59.337573402Z 74 PC: 12d4d | Reallocate memory
2018-12-17T22:55:59.342059624Z 37 PC: 15ce9 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:55:59.356653863Z 74 PC: 18877 | Reallocate memory
2018-12-17T22:55:59.358995141Z 75 PC: 1880f | Execute program
2018-12-17T22:55:59.380014725Z 80 PC: 2c8b9 | Set current PSP
2018-12-17T22:55:59.380788282Z 48 PC: 2c8be | Get DOS version
2018-12-17T22:55:59.38219449Z 99 PC: 330a0 | Get DBCS lead byte table pointer
2018-12-17T22:55:59.385117243Z 101 PC: 2c944 | Get extended country info
2018-12-17T22:55:59.386336929Z 99 PC: 2c94a | Get DBCS lead byte table pointer
2018-12-17T22:55:59.388016999Z 74 PC: 2c9ac | Reallocate memory
2018-12-17T22:55:59.389793778Z 25 PC: 2c9e3 | Get default drive
2018-12-17T22:55:59.390803409Z 37 PC: 2c4a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:55:59.391757604Z 37 PC: 2c4aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:59.393402916Z 37 PC: 2c4b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:59.397653795Z 74 PC: 2b64c | Reallocate memory
2018-12-17T22:55:59.398923079Z 72 PC: 2b68d | Allocate memory
2018-12-17T22:55:59.401009645Z 72 PC: 2b6c5 | Allocate memory
2018-12-17T22:55:59.402604528Z 72 PC: 2b6cd | Allocate memory