Sample viewer

vx.netlux.org/Trojan.DOS.4459

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:52.698630762Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:01:52.700055299Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:52.701588946Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:01:52.703224141Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:01:52.706146823Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:01:52.707477555Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:52.708782459Z 74 PC: 12b19 | Reallocate memory
2018-12-17T23:01:52.712878394Z 37 PC: 12bef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:01:52.714091957Z 37 PC: 12bfa | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:01:52.715186756Z 37 PC: 12c05 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:01:52.716219706Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:01:52.718336095Z 76 PC: 12b98 | Terminate with return code (Return code = '255')