Sample viewer

vx.netlux.org/Trojan.DOS.Haha

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:23.670937989Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:01:23.672377066Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:23.674197303Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:23.675627488Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:23.678010067Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:23.679367159Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:23.680706073Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:01:23.68331384Z 68 PC: 13b13 | I/O control for devices (Set for = ' ')
2018-12-17T22:01:23.685430682Z 68 PC: 13b13 | I/O control for devices (Set for = ' ')
2018-12-17T22:01:23.689611128Z 64 PC: 141f1 | Write file or device (Write 23 bytes on handle 1)
2018-12-17T22:01:23.699243753Z 64 PC: 141f1 | Write file or device (Write 24 bytes on handle 1)
2018-12-17T22:01:23.702928347Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:23.703909836Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:23.704858763Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:23.707596833Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:23.708731597Z 76 PC: 12b9c | Terminate with return code (Return code = '0')