Sample viewer

vx.netlux.org/Trojan.DOS.Shater

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:33.062503693Z 48 PC: 12f37 | Get DOS version
2018-12-17T22:21:33.066058033Z 74 PC: 12cf6 | Reallocate memory
2018-12-17T22:21:33.067866459Z 74 PC: 12cfa | Reallocate memory
2018-12-17T22:21:33.135743748Z 74 PC: 15c23 | Reallocate memory
2018-12-17T22:21:33.139073104Z 75 PC: 15d33 | Execute program
2018-12-17T22:21:33.160506158Z 80 PC: 2a539 | Set current PSP
2018-12-17T22:21:33.161306392Z 48 PC: 2a53e | Get DOS version
2018-12-17T22:21:33.163137133Z 99 PC: 30d20 | Get DBCS lead byte table pointer
2018-12-17T22:21:33.165620941Z 101 PC: 2a5c4 | Get extended country info
2018-12-17T22:21:33.166890063Z 99 PC: 2a5ca | Get DBCS lead byte table pointer
2018-12-17T22:21:33.16848177Z 74 PC: 2a62c | Reallocate memory
2018-12-17T22:21:33.170258433Z 25 PC: 2a663 | Get default drive
2018-12-17T22:21:33.171396151Z 37 PC: 2a123 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:21:33.172858717Z 37 PC: 2a12a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:33.174229137Z 37 PC: 2a131 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:33.1783793Z 74 PC: 292cc | Reallocate memory
2018-12-17T22:21:33.181062551Z 72 PC: 2930d | Allocate memory
2018-12-17T22:21:33.182505128Z 72 PC: 29345 | Allocate memory
2018-12-17T22:21:33.185077487Z 72 PC: 2934d | Allocate memory