Sample viewer

vx.netlux.org/Trojan.DOS.XMas

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:12:03.64604756Z 74 PC: 12a8f | Reallocate memory
2018-12-17T22:12:03.648771038Z 41 PC: 12af6 | Parse filename
2018-12-17T22:12:03.650635004Z 41 PC: 12afe | Parse filename
2018-12-17T22:12:03.65248925Z 75 PC: 12b1a | Execute program
2018-12-17T22:12:03.673432249Z 80 PC: 14f69 | Set current PSP
2018-12-17T22:12:03.674339351Z 48 PC: 14f6e | Get DOS version
2018-12-17T22:12:03.676127674Z 99 PC: 1b750 | Get DBCS lead byte table pointer
2018-12-17T22:12:03.679039324Z 101 PC: 14ff4 | Get extended country info
2018-12-17T22:12:03.681995871Z 99 PC: 14ffa | Get DBCS lead byte table pointer
2018-12-17T22:12:03.688729895Z 74 PC: 1505c | Reallocate memory
2018-12-17T22:12:03.690152893Z 25 PC: 15093 | Get default drive
2018-12-17T22:12:03.691586508Z 37 PC: 14b53 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:12:03.692630456Z 37 PC: 14b5a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:12:03.6937258Z 37 PC: 14b61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:03.698610009Z 74 PC: 13cfc | Reallocate memory
2018-12-17T22:12:03.700212371Z 72 PC: 13d3d | Allocate memory
2018-12-17T22:12:03.70261092Z 72 PC: 13d75 | Allocate memory
2018-12-17T22:12:03.705418404Z 72 PC: 13d7d | Allocate memory