Sample viewer

vx.netlux.org/Trojan.DOS.Erkle

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:53.512984519Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:03:53.514390634Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:53.518900137Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:03:53.522864635Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:03:53.524625788Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:03:53.526840394Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:53.528304818Z 74 PC: 12af4 | Reallocate memory
2018-12-17T23:03:53.530359172Z 68 PC: 135e0 | I/O control for devices (Set for = '�,')
2018-12-17T23:03:53.534767224Z 68 PC: 135e0 | I/O control for devices (Set for = '�,')
2018-12-17T23:03:53.538232333Z 28 PC: 1356a | Get allocation info for specified drive
2018-12-17T23:03:53.560774958Z 28 PC: 1356a | Get allocation info for specified drive