Sample viewer

vx.netlux.org/Trojan.DOS.Rivvi

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:40.219959095Z 48 PC: 12a4c | Get DOS version
2018-12-17T21:53:40.221461874Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:40.222552807Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:53:40.22365191Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:53:40.225373584Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:53:40.226501733Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:53:40.227744002Z 74 PC: 12af4 | Reallocate memory
2018-12-17T21:53:40.230505311Z 68 PC: 13033 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T21:53:40.232447071Z 68 PC: 13033 | I/O control for devices (Set for = '')
2018-12-17T21:53:40.235975362Z 68 PC: 13033 | I/O control for devices (Set for = '')
2018-12-17T21:53:40.241172528Z 64 PC: 14d4e | Write file or device (Write 29 bytes on handle 1)
2018-12-17T21:53:40.244680647Z 64 PC: 14d4e | Write file or device (Write 32 bytes on handle 1)
2018-12-17T21:53:40.249009649Z 7 PC: 13b80 | Direct console input without echo