Sample viewer

vx.netlux.org/Trojan.DOS.Delarm.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:15:09.829291035Z 60 PC: 12a86 | Create or truncate file
2018-12-17T22:15:09.846206177Z 64 PC: 12a9f | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:15:09.84978799Z 64 PC: 12ab1 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.852303677Z 64 PC: 12ac3 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.855272989Z 64 PC: 12b22 | Write file or device (Write 79 bytes on handle 5)
2018-12-17T22:15:09.85816667Z 64 PC: 12b34 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.860794282Z 64 PC: 12b5a | Write file or device (Write 22 bytes on handle 5)
2018-12-17T22:15:09.863819897Z 64 PC: 12b6c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.866735143Z 64 PC: 12b91 | Write file or device (Write 21 bytes on handle 5)
2018-12-17T22:15:09.869347891Z 64 PC: 12ba3 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.871806861Z 64 PC: 12bc0 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:15:09.877658167Z 64 PC: 12bd2 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.880260189Z 64 PC: 12bf1 | Write file or device (Write 15 bytes on handle 5)
2018-12-17T22:15:09.88270648Z 64 PC: 12c03 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.885859545Z 64 PC: 12c22 | Write file or device (Write 15 bytes on handle 5)
2018-12-17T22:15:09.888417914Z 64 PC: 12c34 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:15:09.891048142Z 64 PC: 12c59 | Write file or device (Write 21 bytes on handle 5)
2018-12-17T22:15:09.894654965Z 62 PC: 12c60 | Close file
2018-12-17T22:15:09.902906599Z 81 PC: 12d3e | Get current PSP
2018-12-17T22:15:09.903670471Z 74 PC: 12d4e | Reallocate memory
2018-12-17T22:15:09.906854348Z 75 PC: 12dc2 | Execute program
2018-12-17T22:15:09.927286839Z 80 PC: 2b729 | Set current PSP
2018-12-17T22:15:09.928076909Z 48 PC: 2b72e | Get DOS version
2018-12-17T22:15:09.929857998Z 99 PC: 31f10 | Get DBCS lead byte table pointer
2018-12-17T22:15:09.932683276Z 101 PC: 2b7b4 | Get extended country info
2018-12-17T22:15:09.933991593Z 99 PC: 2b7ba | Get DBCS lead byte table pointer
2018-12-17T22:15:09.936235245Z 74 PC: 2b81c | Reallocate memory
2018-12-17T22:15:09.938125502Z 25 PC: 2b853 | Get default drive
2018-12-17T22:15:09.939981062Z 37 PC: 2b313 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:15:09.941909636Z 37 PC: 2b31a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:15:09.944309186Z 37 PC: 2b321 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:15:09.949240886Z 74 PC: 2a4bc | Reallocate memory
2018-12-17T22:15:09.950898914Z 72 PC: 2a4fd | Allocate memory
2018-12-17T22:15:09.953994459Z 72 PC: 2a535 | Allocate memory
2018-12-17T22:15:09.955952874Z 72 PC: 2a53d | Allocate memory