Sample viewer

vx.netlux.org/Trojan.DOS.Wiz.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:09.501066009Z 48 PC: 13161 | Get DOS version
2018-12-17T22:59:09.504442395Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:59:09.506255673Z 74 PC: 12d49 | Reallocate memory
2018-12-17T22:59:09.507911475Z 74 PC: 12d4d | Reallocate memory
2018-12-17T22:59:09.513833334Z 37 PC: 15ce9 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:59:09.518755896Z 42 PC: 18596 | Get date 0x18596: mov al, dh
0x18598: call 0x185d7
0x1859b: mov al, dl
0x1859d: call 0x185d3
0x185a0: mov al, 0x14
0x185a2: sub cx, 0x7d0
0x185a6: jae 0x185ad
0x185a8: dec al
0x185aa: add cx, 0x64
0x185ad: call 0x185d3
0x185b0: mov al, cl
0x185b2: call 0x185d7
0x185b5: sub di, 0xa
0x185b8: mov ds, word ptr [4]
0x185bc: push bp
0x185bd: sub word ptr [0x86], 4
0x185c2: mov bp, word ptr [0x86]
0x185c6: mov word ptr [bp + 2], di
0x185c9: mov word ptr [bp], 0xa
0x185ce: pop bp
2018-12-17T22:59:09.524355921Z 37 PC: 15c41 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:59:09.528233549Z 76 PC: 12c16 | Terminate with return code (Return code = '0')