Sample viewer

vx.netlux.org/Trojan.DOS.FormatC.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:38.667040202Z 74 PC: 12a53 | Reallocate memory
2018-12-17T23:10:38.672771889Z 41 PC: 12aba | Parse filename
2018-12-17T23:10:38.675097077Z 41 PC: 12ac2 | Parse filename
2018-12-17T23:10:38.67706655Z 75 PC: 12add | Execute program
2018-12-17T23:10:38.703431436Z 80 PC: 14b59 | Set current PSP
2018-12-17T23:10:38.705289086Z 48 PC: 14b5e | Get DOS version
2018-12-17T23:10:38.707316623Z 99 PC: 1b340 | Get DBCS lead byte table pointer
2018-12-17T23:10:38.710659364Z 101 PC: 14be4 | Get extended country info
2018-12-17T23:10:38.713888073Z 99 PC: 14bea | Get DBCS lead byte table pointer
2018-12-17T23:10:38.715892234Z 74 PC: 14c4c | Reallocate memory
2018-12-17T23:10:38.717887809Z 25 PC: 14c83 | Get default drive
2018-12-17T23:10:38.720177092Z 37 PC: 14743 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:10:38.722225072Z 37 PC: 1474a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:10:38.72397183Z 37 PC: 14751 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:38.729534385Z 74 PC: 138ec | Reallocate memory
2018-12-17T23:10:38.732092567Z 72 PC: 1392d | Allocate memory
2018-12-17T23:10:38.734585244Z 72 PC: 13965 | Allocate memory
2018-12-17T23:10:38.737374697Z 72 PC: 1396d | Allocate memory