Sample viewer

vx.netlux.org/Trojan.DOS.Orion

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:05.592689815Z 48 PC: 12a4c | Get DOS version
2018-12-17T23:11:05.597976903Z 53 PC: 12bab | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:05.603184368Z 53 PC: 12bb8 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:11:05.615168805Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:11:05.616873775Z 53 PC: 12bd2 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:11:05.618245053Z 37 PC: 12be6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:05.619386771Z 64 PC: 12c5f | Write file or device (Write 30 bytes on handle 2)
2018-12-17T23:11:05.622408898Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:11:05.624060592Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:11:05.625741488Z 37 PC: 12c08 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T23:11:05.627357947Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T23:11:05.63003602Z 76 PC: 12b9c | Terminate with return code (Return code = '3')