Sample viewer

vx.netlux.org/Trojan.DOS.Covina

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:37.762453328Z 74 PC: 12b00 | Reallocate memory
2018-12-17T23:11:37.766215423Z 41 PC: 12bfe | Parse filename
2018-12-17T23:11:37.767864314Z 41 PC: 12c10 | Parse filename
2018-12-17T23:11:37.769311987Z 75 PC: 12c2c | Execute program
2018-12-17T23:11:37.791585756Z 80 PC: 14d69 | Set current PSP
2018-12-17T23:11:37.792955462Z 48 PC: 14d6e | Get DOS version
2018-12-17T23:11:37.794462978Z 99 PC: 1b550 | Get DBCS lead byte table pointer
2018-12-17T23:11:37.797112831Z 101 PC: 14df4 | Get extended country info
2018-12-17T23:11:37.799700778Z 99 PC: 14dfa | Get DBCS lead byte table pointer
2018-12-17T23:11:37.803894395Z 74 PC: 14e5c | Reallocate memory
2018-12-17T23:11:37.805848069Z 25 PC: 14e93 | Get default drive
2018-12-17T23:11:37.808187619Z 37 PC: 14953 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:11:37.810273432Z 37 PC: 1495a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:37.822365373Z 37 PC: 14961 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:37.827860478Z 74 PC: 13afc | Reallocate memory
2018-12-17T23:11:37.82950415Z 72 PC: 13b3d | Allocate memory
2018-12-17T23:11:37.831305638Z 72 PC: 13b75 | Allocate memory
2018-12-17T23:11:37.834221532Z 72 PC: 13b7d | Allocate memory