Sample viewer

vx.netlux.org/Trojan.DOS.7472

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:19.829652471Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:01:19.832724649Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:19.83383821Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:19.83489895Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:19.836498785Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:19.837604025Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:19.838817155Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:01:19.842064602Z 26 PC: 13f54 | Set disk transfer address
2018-12-17T22:01:19.843076249Z 78 PC: 13f5e | Find first file