Sample viewer

vx.netlux.org/Trojan.DOS.Vzlom.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:05.581928476Z 61 PC: 12b6f | Open file (Filename = 'big_jopa.exe')
2018-12-17T22:02:05.58873501Z 64 PC: 12b7a | Write file or device (Write 5000 bytes on handle 2)
2018-12-17T22:02:05.59141506Z 62 PC: 12b7e | Close file
2018-12-17T22:02:05.592995378Z 61 PC: 12b86 | Open file (Filename = 'dn.vwr')
2018-12-17T22:02:05.59902704Z 64 PC: 12b90 | Write file or device (Write 25 bytes on handle 2)
2018-12-17T22:02:05.600452324Z 62 PC: 12b94 | Close file
2018-12-17T22:02:05.601855826Z 53 PC: 12b9d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:02:05.603201978Z 37 PC: 12bae | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:02:05.605029059Z 49 PC: 12bb5 | Terminate and stay resident (Return code = '28' | Memory size = '1753')