Sample viewer

vx.netlux.org/Trojan.DOS.Draw.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:05:04.014881436Z 74 PC: 12a52 | Reallocate memory
2018-12-17T22:05:04.017486266Z 60 PC: 12a76 | Create or truncate file
2018-12-17T22:05:04.022852111Z 75 PC: 12ae8 | Execute program
2018-12-17T22:05:04.051023716Z 80 PC: 14d29 | Set current PSP
2018-12-17T22:05:04.052556462Z 48 PC: 14d2e | Get DOS version
2018-12-17T22:05:04.054991772Z 99 PC: 1b510 | Get DBCS lead byte table pointer
2018-12-17T22:05:04.05791561Z 101 PC: 14db4 | Get extended country info
2018-12-17T22:05:04.059477149Z 99 PC: 14dba | Get DBCS lead byte table pointer
2018-12-17T22:05:04.06220579Z 74 PC: 14e1c | Reallocate memory
2018-12-17T22:05:04.063972681Z 25 PC: 14e53 | Get default drive
2018-12-17T22:05:04.065454894Z 37 PC: 14913 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:05:04.067708115Z 37 PC: 1491a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:04.06894934Z 37 PC: 14921 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:04.07320793Z 74 PC: 13abc | Reallocate memory
2018-12-17T22:05:04.075502171Z 72 PC: 13afd | Allocate memory
2018-12-17T22:05:04.07749406Z 72 PC: 13b35 | Allocate memory
2018-12-17T22:05:04.079532418Z 72 PC: 13b3d | Allocate memory