Sample viewer

vx.netlux.org/Trojan.DOS.Sam.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:05:04.619330353Z 74 PC: 12b06 | Reallocate memory
2018-12-17T22:05:04.63781008Z 60 PC: 12bb1 | Create or truncate file
2018-12-17T22:05:04.642946087Z 69 PC: 12bcf | Duplicate handle
2018-12-17T22:05:04.644647054Z 70 PC: 12bda | Redirect handle
2018-12-17T22:05:04.647418816Z 41 PC: 12c3b | Parse filename
2018-12-17T22:05:04.649901543Z 41 PC: 12c43 | Parse filename
2018-12-17T22:05:04.651897479Z 75 PC: 12c5f | Execute program
2018-12-17T22:05:04.683581189Z 80 PC: 14f89 | Set current PSP
2018-12-17T22:05:04.685328126Z 48 PC: 14f8e | Get DOS version
2018-12-17T22:05:04.690729211Z 99 PC: 1b770 | Get DBCS lead byte table pointer
2018-12-17T22:05:04.693434087Z 101 PC: 15014 | Get extended country info
2018-12-17T22:05:04.69674347Z 99 PC: 1501a | Get DBCS lead byte table pointer
2018-12-17T22:05:04.698007323Z 74 PC: 1507c | Reallocate memory
2018-12-17T22:05:04.69934803Z 25 PC: 150b3 | Get default drive
2018-12-17T22:05:04.711462411Z 37 PC: 14b73 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:05:04.71278738Z 37 PC: 14b7a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:05:04.713948511Z 37 PC: 14b81 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:04.719436663Z 74 PC: 13d1c | Reallocate memory
2018-12-17T22:05:04.720910721Z 72 PC: 13d5d | Allocate memory
2018-12-17T22:05:04.722437934Z 72 PC: 13d95 | Allocate memory
2018-12-17T22:05:04.724787738Z 72 PC: 13d9d | Allocate memory