Sample viewer

vx.netlux.org/Trojan.DOS.QB2Cduck

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:48.843285423Z 74 PC: 12a8f | Reallocate memory
2018-12-17T22:19:48.845426038Z 41 PC: 12af6 | Parse filename
2018-12-17T22:19:48.848085124Z 41 PC: 12afe | Parse filename
2018-12-17T22:19:48.849866644Z 75 PC: 12b1a | Execute program
2018-12-17T22:19:48.872796701Z 80 PC: 14dc9 | Set current PSP
2018-12-17T22:19:48.87454571Z 48 PC: 14dce | Get DOS version
2018-12-17T22:19:48.87563154Z 99 PC: 1b5b0 | Get DBCS lead byte table pointer
2018-12-17T22:19:48.877359074Z 101 PC: 14e54 | Get extended country info
2018-12-17T22:19:48.878694029Z 99 PC: 14e5a | Get DBCS lead byte table pointer
2018-12-17T22:19:48.879710216Z 74 PC: 14ebc | Reallocate memory
2018-12-17T22:19:48.880767251Z 25 PC: 14ef3 | Get default drive
2018-12-17T22:19:48.882032544Z 37 PC: 149b3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:48.882918276Z 37 PC: 149ba | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:48.883784536Z 37 PC: 149c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:48.886861661Z 74 PC: 13b5c | Reallocate memory
2018-12-17T22:19:48.88796846Z 72 PC: 13b9d | Allocate memory
2018-12-17T22:19:48.88917296Z 72 PC: 13bd5 | Allocate memory
2018-12-17T22:19:48.890631462Z 72 PC: 13bdd | Allocate memory