Sample viewer

vx.netlux.org/Trojan.DOS.Tag

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:28.359636176Z 74 PC: 12a8f | Reallocate memory
2018-12-17T22:19:28.362290457Z 26 PC: 12aa4 | Set disk transfer address
2018-12-17T22:19:28.363736403Z 78 PC: 12aac | Find first file
2018-12-17T22:19:28.374237043Z 41 PC: 12b0b | Parse filename
2018-12-17T22:19:28.376565219Z 41 PC: 12b13 | Parse filename
2018-12-17T22:19:28.378071626Z 75 PC: 12b2f | Execute program
2018-12-17T22:19:28.397362877Z 80 PC: 14cb9 | Set current PSP
2018-12-17T22:19:28.398719578Z 48 PC: 14cbe | Get DOS version
2018-12-17T22:19:28.400918802Z 99 PC: 1b4a0 | Get DBCS lead byte table pointer
2018-12-17T22:19:28.404443371Z 101 PC: 14d44 | Get extended country info
2018-12-17T22:19:28.4059917Z 99 PC: 14d4a | Get DBCS lead byte table pointer
2018-12-17T22:19:28.412604576Z 74 PC: 14dac | Reallocate memory
2018-12-17T22:19:28.41426996Z 25 PC: 14de3 | Get default drive
2018-12-17T22:19:28.415596925Z 37 PC: 148a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:28.417915497Z 37 PC: 148aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:28.419262312Z 37 PC: 148b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:28.423723207Z 74 PC: 13a4c | Reallocate memory
2018-12-17T22:19:28.435040964Z 72 PC: 13a8d | Allocate memory
2018-12-17T22:19:28.436512296Z 72 PC: 13ac5 | Allocate memory
2018-12-17T22:19:28.438049413Z 72 PC: 13acd | Allocate memory