Sample viewer

vx.netlux.org/Trojan.DOS.ExecSpy

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:03:53.276976822Z 226 PC: 13628 | UNKNOWN!
2018-12-17T22:03:53.280171299Z 48 PC: 12ae1 | Get DOS version
2018-12-17T22:03:53.281808176Z 9 PC: 12af0 | Display string (Could not find end pointer)
2018-12-17T22:03:53.289517506Z 74 PC: 12b5c | Reallocate memory
2018-12-17T22:03:53.292385707Z 37 PC: 12b70 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:03:53.293653651Z 51 PC: 12dd8 | Get or set Ctrl-Break
2018-12-17T22:03:53.294784823Z 51 PC: 12de3 | Get or set Ctrl-Break
2018-12-17T22:03:53.296737991Z 72 PC: 12fbd | Allocate memory
2018-12-17T22:03:53.299023642Z 41 PC: 13038 | Parse filename
2018-12-17T22:03:53.301090675Z 41 PC: 13041 | Parse filename
2018-12-17T22:03:53.303430655Z 98 PC: 9f983 | Get current PSP
2018-12-17T22:03:53.305171111Z 42 PC: 9f99c | Get date 0x9f99c: pop si
0x9f99d: mov byte ptr es:[si], 0x20
0x9f9a1: inc si
0x9f9a2: mov byte ptr es:[si], 0x20
0x9f9a6: xor ax, ax
0x9f9a8: mov al, dl
0x9f9aa: mov bx, si
0x9f9ac: push cs
0x9f9ad: call 0x9fa7f
0x9f9b0: nop
0x9f9b1: add si, cx
0x9f9b3: inc si
0x9f9b4: mov byte ptr es:[si], 0x2d
0x9f9b8: inc si
0x9f9b9: mov bx, si
0x9f9bb: xor ax, ax
0x9f9bd: mov al, dh
0x9f9bf: push cs
0x9f9c0: call 0x9fa7f
0x9f9c3: nop
2018-12-17T22:03:53.308381307Z 44 PC: 9f9d1 | Get time 0x9f9d1: pop si
0x9f9d2: push cx
0x9f9d3: mov bx, si
0x9f9d5: xor ax, ax
0x9f9d7: mov al, ch
0x9f9d9: push cs
0x9f9da: call 0x9fa7f
0x9f9dd: nop
0x9f9de: add si, cx
0x9f9e0: mov byte ptr es:[si], 0x3a
0x9f9e4: inc si
0x9f9e5: pop cx
0x9f9e6: xor ax, ax
0x9f9e8: mov bx, si
0x9f9ea: mov al, cl
0x9f9ec: push cs
0x9f9ed: call 0x9fa7f
0x9f9f0: nop
0x9f9f1: add si, cx
0x9f9f3: mov byte ptr es:[si], 0xd
2018-12-17T22:03:53.311199881Z 91 PC: 9fa27 | Create new file
2018-12-17T22:03:54.003662759Z 87 PC: 9fa3a | Get or set file date and time
2018-12-17T22:03:54.005064649Z 66 PC: 9fa6b | Move file pointer
2018-12-17T22:03:54.006440179Z 64 PC: 9fa4e | Write file or device (Write 67 bytes on handle 5)
2018-12-17T22:03:54.015347318Z 87 PC: 9fa55 | Get or set file date and time
2018-12-17T22:03:54.017223828Z 62 PC: 9fa59 | Close file
2018-12-17T22:03:54.030861167Z 75 PC: 1300b | Execute program