Sample viewer

vx.netlux.org/Trojan.DOS.UFH

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:58.34602275Z 74 PC: 34d32 | Reallocate memory
2018-12-17T23:06:58.35388988Z 74 PC: 35396 | Reallocate memory
2018-12-17T23:06:58.35535818Z 48 PC: 34425 | Get DOS version
2018-12-17T23:06:58.37898133Z 48 PC: 12f93 | Get DOS version
2018-12-17T23:06:58.381574665Z 43 PC: 131c8 | Set date
2018-12-17T23:06:58.384704699Z 74 PC: 12d7b | Reallocate memory
2018-12-17T23:06:58.387809496Z 74 PC: 12d7f | Reallocate memory
2018-12-17T23:06:58.461837673Z 81 PC: 161aa | Get current PSP
2018-12-17T23:06:58.462704062Z 74 PC: 161bb | Reallocate memory
2018-12-17T23:06:58.465385252Z 75 PC: 162ce | Execute program
2018-12-17T23:06:58.481567674Z 80 PC: 2c3a9 | Set current PSP
2018-12-17T23:06:58.48251241Z 48 PC: 2c3ae | Get DOS version
2018-12-17T23:06:58.484652633Z 99 PC: 32b90 | Get DBCS lead byte table pointer
2018-12-17T23:06:58.487687909Z 101 PC: 2c434 | Get extended country info
2018-12-17T23:06:58.489036365Z 99 PC: 2c43a | Get DBCS lead byte table pointer
2018-12-17T23:06:58.490853851Z 74 PC: 2c49c | Reallocate memory
2018-12-17T23:06:58.492632325Z 25 PC: 2c4d3 | Get default drive
2018-12-17T23:06:58.493683561Z 37 PC: 2bf93 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:06:58.495759684Z 37 PC: 2bf9a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:06:58.496899858Z 37 PC: 2bfa1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:58.500413904Z 74 PC: 2b13c | Reallocate memory
2018-12-17T23:06:58.502781064Z 72 PC: 2b17d | Allocate memory
2018-12-17T23:06:58.504328422Z 72 PC: 2b1b5 | Allocate memory
2018-12-17T23:06:58.505942346Z 72 PC: 2b1bd | Allocate memory