Sample viewer

vx.netlux.org/Trojan.DOS.Krepper.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:41.339159212Z 48 PC: 12f37 | Get DOS version
2018-12-17T21:51:41.343106175Z 74 PC: 12cf6 | Reallocate memory
2018-12-17T21:51:41.344978118Z 74 PC: 12cfa | Reallocate memory
2018-12-17T21:51:41.414877075Z 74 PC: 15c11 | Reallocate memory
2018-12-17T21:51:41.418724863Z 75 PC: 15d21 | Execute program
2018-12-17T21:51:41.439636478Z 80 PC: 29269 | Set current PSP
2018-12-17T21:51:41.440950806Z 48 PC: 2926e | Get DOS version
2018-12-17T21:51:41.443961937Z 99 PC: 2fa50 | Get DBCS lead byte table pointer
2018-12-17T21:51:41.446978346Z 101 PC: 292f4 | Get extended country info
2018-12-17T21:51:41.448541814Z 99 PC: 292fa | Get DBCS lead byte table pointer
2018-12-17T21:51:41.45123097Z 74 PC: 2935c | Reallocate memory
2018-12-17T21:51:41.452992406Z 25 PC: 29393 | Get default drive
2018-12-17T21:51:41.45462358Z 37 PC: 28e53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:51:41.469961701Z 37 PC: 28e5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:51:41.471610294Z 37 PC: 28e61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:51:41.476069788Z 74 PC: 27ffc | Reallocate memory
2018-12-17T21:51:41.47792863Z 72 PC: 2803d | Allocate memory
2018-12-17T21:51:41.479795568Z 72 PC: 28075 | Allocate memory
2018-12-17T21:51:41.48156194Z 72 PC: 2807d | Allocate memory