Sample viewer

vx.netlux.org/Trojan.DOS.Welcome

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:17:46.485219948Z 74 PC: 12b06 | Reallocate memory
2018-12-17T22:17:46.487747749Z 60 PC: 12b3b | Create or truncate file
2018-12-17T22:17:46.492779923Z 69 PC: 12b59 | Duplicate handle
2018-12-17T22:17:46.499171332Z 70 PC: 12b64 | Redirect handle
2018-12-17T22:17:46.502128478Z 41 PC: 12bc5 | Parse filename
2018-12-17T22:17:46.504630295Z 41 PC: 12bcd | Parse filename
2018-12-17T22:17:46.50634867Z 75 PC: 12be9 | Execute program
2018-12-17T22:17:46.527015149Z 80 PC: 14c59 | Set current PSP
2018-12-17T22:17:46.528935342Z 48 PC: 14c5e | Get DOS version
2018-12-17T22:17:46.530795166Z 99 PC: 1b440 | Get DBCS lead byte table pointer
2018-12-17T22:17:46.533670277Z 101 PC: 14ce4 | Get extended country info
2018-12-17T22:17:46.545611774Z 99 PC: 14cea | Get DBCS lead byte table pointer
2018-12-17T22:17:46.547123382Z 74 PC: 14d4c | Reallocate memory
2018-12-17T22:17:46.548782047Z 25 PC: 14d83 | Get default drive
2018-12-17T22:17:46.550705631Z 37 PC: 14843 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:17:46.551828371Z 37 PC: 1484a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:17:46.553078555Z 37 PC: 14851 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:17:46.561447715Z 74 PC: 139ec | Reallocate memory
2018-12-17T22:17:46.577771455Z 72 PC: 13a2d | Allocate memory
2018-12-17T22:17:46.580263453Z 72 PC: 13a65 | Allocate memory
2018-12-17T22:17:46.582925472Z 72 PC: 13a6d | Allocate memory