Sample viewer

vx.netlux.org/Trojan.DOS.DmD

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:04:44.871963738Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:04:44.874124678Z 41 PC: 12aba | Parse filename
2018-12-17T22:04:44.875970623Z 41 PC: 12ac2 | Parse filename
2018-12-17T22:04:44.877653228Z 75 PC: 12ade | Execute program
2018-12-17T22:04:44.897943929Z 80 PC: 14f59 | Set current PSP
2018-12-17T22:04:44.898920113Z 48 PC: 14f5e | Get DOS version
2018-12-17T22:04:44.900477387Z 99 PC: 1b740 | Get DBCS lead byte table pointer
2018-12-17T22:04:44.903105405Z 101 PC: 14fe4 | Get extended country info
2018-12-17T22:04:44.904749717Z 99 PC: 14fea | Get DBCS lead byte table pointer
2018-12-17T22:04:44.905967934Z 74 PC: 1504c | Reallocate memory
2018-12-17T22:04:44.907342928Z 25 PC: 15083 | Get default drive
2018-12-17T22:04:44.908640838Z 37 PC: 14b43 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:04:44.909672836Z 37 PC: 14b4a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:44.910692001Z 37 PC: 14b51 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:44.915541295Z 74 PC: 13cec | Reallocate memory
2018-12-17T22:04:44.917539298Z 72 PC: 13d2d | Allocate memory
2018-12-17T22:04:44.919477615Z 72 PC: 13d65 | Allocate memory
2018-12-17T22:04:44.921920359Z 72 PC: 13d6d | Allocate memory