Sample viewer

vx.netlux.org/Trojan.DOS.AMDV

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:44.09857753Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:05:44.101507329Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:44.103189722Z 53 PC: 12b89 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:05:44.104846187Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:05:44.107245408Z 53 PC: 12ba3 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:05:44.108877627Z 37 PC: 12bb7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:44.110385853Z 74 PC: 12acf | Reallocate memory
2018-12-17T23:05:44.113292879Z 68 PC: 134f8 | I/O control for devices (Set for = '��')
2018-12-17T23:05:44.117657315Z 74 PC: 13534 | Reallocate memory
2018-12-17T23:05:44.120441781Z 68 PC: 134f8 | I/O control for devices (Set for = 'Turbo C++ - Copyright 1990 Borland Intl.')
2018-12-17T23:05:44.123507526Z 28 PC: 1347b | Get allocation info for specified drive
2018-12-17T23:05:45.113866027Z 37 PC: 12bc3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:05:45.115565443Z 37 PC: 12bce | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:05:45.117152708Z 37 PC: 12bd9 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:05:45.119784566Z 37 PC: 12be4 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:05:45.121792391Z 76 PC: 12b6d | Terminate with return code (Return code = '0')