Sample viewer

vx.netlux.org/Trojan.DOS.DelAll.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:59.00714956Z 74 PC: 12a52 | Reallocate memory
2018-12-17T22:22:59.009767688Z 75 PC: 12aa7 | Execute program
2018-12-17T22:22:59.030505748Z 80 PC: 151f9 | Set current PSP
2018-12-17T22:22:59.031266628Z 48 PC: 151fe | Get DOS version
2018-12-17T22:22:59.033610878Z 99 PC: 1b9e0 | Get DBCS lead byte table pointer
2018-12-17T22:22:59.037858641Z 101 PC: 15284 | Get extended country info
2018-12-17T22:22:59.039158621Z 99 PC: 1528a | Get DBCS lead byte table pointer
2018-12-17T22:22:59.04043961Z 74 PC: 152ec | Reallocate memory
2018-12-17T22:22:59.042326946Z 25 PC: 15323 | Get default drive
2018-12-17T22:22:59.043961412Z 37 PC: 14de3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:22:59.045841261Z 37 PC: 14dea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:22:59.050730391Z 37 PC: 14df1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:59.054977927Z 74 PC: 13f8c | Reallocate memory
2018-12-17T22:22:59.056591543Z 72 PC: 13fcd | Allocate memory
2018-12-17T22:22:59.058845552Z 72 PC: 14005 | Allocate memory
2018-12-17T22:22:59.061068952Z 72 PC: 1400d | Allocate memory