Sample viewer

vx.netlux.org/Trojan.DOS.Hklove

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:41.885441022Z 48 PC: 12f29 | Get DOS version
2018-12-17T23:12:41.890323521Z 74 PC: 12cec | Reallocate memory
2018-12-17T23:12:41.892155978Z 74 PC: 12cf0 | Reallocate memory
2018-12-17T23:12:41.901419136Z 74 PC: 15325 | Reallocate memory
2018-12-17T23:12:41.905449093Z 75 PC: 15440 | Execute program
2018-12-17T23:12:41.929391422Z 80 PC: 268d9 | Set current PSP
2018-12-17T23:12:41.930696158Z 48 PC: 268de | Get DOS version
2018-12-17T23:12:41.933541117Z 99 PC: 2d0c0 | Get DBCS lead byte table pointer
2018-12-17T23:12:41.93635622Z 101 PC: 26964 | Get extended country info
2018-12-17T23:12:41.937492262Z 99 PC: 2696a | Get DBCS lead byte table pointer
2018-12-17T23:12:41.93877834Z 74 PC: 269cc | Reallocate memory
2018-12-17T23:12:41.940568768Z 25 PC: 26a03 | Get default drive
2018-12-17T23:12:41.942119166Z 37 PC: 264c3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:12:41.943641746Z 37 PC: 264ca | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:12:41.94532427Z 37 PC: 264d1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:41.950051929Z 74 PC: 2566c | Reallocate memory
2018-12-17T23:12:41.951474586Z 72 PC: 256ad | Allocate memory
2018-12-17T23:12:41.953505712Z 72 PC: 256e5 | Allocate memory
2018-12-17T23:12:41.955293632Z 72 PC: 256ed | Allocate memory