Sample viewer

vx.netlux.org/Trojan.DOS.DelWin.e

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:33.945757724Z 48 PC: 12f29 | Get DOS version
2018-12-17T23:12:33.951035205Z 74 PC: 12cec | Reallocate memory
2018-12-17T23:12:33.953643414Z 74 PC: 12cf0 | Reallocate memory
2018-12-17T23:12:33.963718829Z 74 PC: 15325 | Reallocate memory
2018-12-17T23:12:33.967411103Z 75 PC: 15440 | Execute program
2018-12-17T23:12:33.996115171Z 80 PC: 265b9 | Set current PSP
2018-12-17T23:12:33.99763188Z 48 PC: 265be | Get DOS version
2018-12-17T23:12:33.999980198Z 99 PC: 2cda0 | Get DBCS lead byte table pointer
2018-12-17T23:12:34.004425767Z 101 PC: 26644 | Get extended country info
2018-12-17T23:12:34.006198819Z 99 PC: 2664a | Get DBCS lead byte table pointer
2018-12-17T23:12:34.008344332Z 74 PC: 266ac | Reallocate memory
2018-12-17T23:12:34.010785668Z 25 PC: 266e3 | Get default drive
2018-12-17T23:12:34.012405921Z 37 PC: 261a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:12:34.014362497Z 37 PC: 261aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:34.016740174Z 37 PC: 261b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:34.021933201Z 74 PC: 2534c | Reallocate memory
2018-12-17T23:12:34.023926419Z 72 PC: 2538d | Allocate memory
2018-12-17T23:12:34.026932095Z 72 PC: 253c5 | Allocate memory
2018-12-17T23:12:34.029254754Z 72 PC: 253cd | Allocate memory