Sample viewer

vx.netlux.org/Trojan.DOS.3696

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:24.504236185Z 48 PC: 12a4b | Get DOS version
2018-12-17T23:09:24.506981995Z 53 PC: 12b83 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:24.509025415Z 53 PC: 12b90 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:09:24.510693971Z 53 PC: 12b9d | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:09:24.512548186Z 53 PC: 12baa | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:09:24.514862346Z 37 PC: 12bbe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:24.516850282Z 74 PC: 12af3 | Reallocate memory
2018-12-17T23:09:24.519568571Z 68 PC: 132e3 | I/O control for devices (Set for = '�7')
2018-12-17T23:09:24.523701558Z 68 PC: 132e3 | I/O control for devices (Set for = '� ��')
2018-12-17T23:09:24.527338403Z 28 PC: 1326d | Get allocation info for specified drive
2018-12-17T23:09:24.911173233Z 37 PC: 12bca | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:09:24.913632385Z 37 PC: 12bd5 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:09:24.915405938Z 37 PC: 12be0 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:09:24.917041943Z 37 PC: 12beb | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:09:24.919460769Z 76 PC: 12b74 | Terminate with return code (Return code = '0')