Sample viewer

vx.netlux.org/Trojan.DOS.Spoof

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:52.752236982Z 81 PC: 12a85 | Get current PSP
2018-12-17T23:08:52.754551031Z 61 PC: 12aa1 | Open file (Filename = '8 Out of memory $Unsupported Dos Call. Set FullINT2E = Yes in your 4DOS/NDOS .INI file $ __TEO__.EXE __TEO__.EXE')
2018-12-17T23:08:52.761354485Z 66 PC: 12ab7 | Move file pointer
2018-12-17T23:08:52.763113724Z 60 PC: 12ac4 | Create or truncate file
2018-12-17T23:08:52.781091766Z 72 PC: 12ad0 | Allocate memory
2018-12-17T23:08:52.782771149Z 63 PC: 12af3 | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:08:52.788740371Z 64 PC: 12b35 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:08:52.793947493Z 63 PC: 12af3 | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:08:52.806168551Z 64 PC: 12b35 | Write file or device (Write 4096 bytes on handle 6)
2018-12-17T23:08:52.814613737Z 63 PC: 12af3 | Read file or device (Read 4096 bytes on handle 5)
2018-12-17T23:08:52.822311364Z 64 PC: 12b19 | Write file or device (Write 258 bytes on handle 6)
2018-12-17T23:08:52.827882669Z 62 PC: 12b4a | Close file
2018-12-17T23:08:52.839236735Z 73 PC: 12b54 | Release memory
2018-12-17T23:08:52.841171183Z 81 PC: 12145 | Get current PSP