Sample viewer

vx.netlux.org/Trojan.DOS.Delarm.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:44.616903225Z 60 PC: 12a85 | Create or truncate file
2018-12-17T22:24:44.63501205Z 64 PC: 12a9e | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:24:44.639095426Z 64 PC: 12ab0 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:24:44.642655846Z 64 PC: 12ac2 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:24:44.64573894Z 64 PC: 12b14 | Write file or device (Write 66 bytes on handle 5)
2018-12-17T22:24:44.649630675Z 64 PC: 12b26 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:24:44.653338437Z 64 PC: 12b49 | Write file or device (Write 19 bytes on handle 5)
2018-12-17T22:24:44.656052638Z 64 PC: 12b5b | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:24:44.659536612Z 64 PC: 12b7f | Write file or device (Write 20 bytes on handle 5)
2018-12-17T22:24:44.663178817Z 64 PC: 12b91 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:24:44.665971631Z 62 PC: 12b98 | Close file
2018-12-17T22:24:44.674982552Z 81 PC: 12c76 | Get current PSP
2018-12-17T22:24:44.680677499Z 74 PC: 12c86 | Reallocate memory
2018-12-17T22:24:44.683661595Z 75 PC: 12cfa | Execute program
2018-12-17T22:24:44.705679946Z 80 PC: 2b729 | Set current PSP
2018-12-17T22:24:44.707761423Z 48 PC: 2b72e | Get DOS version
2018-12-17T22:24:44.709732388Z 99 PC: 31f10 | Get DBCS lead byte table pointer
2018-12-17T22:24:44.713102113Z 101 PC: 2b7b4 | Get extended country info
2018-12-17T22:24:44.714288916Z 99 PC: 2b7ba | Get DBCS lead byte table pointer
2018-12-17T22:24:44.715410334Z 74 PC: 2b81c | Reallocate memory
2018-12-17T22:24:44.716645926Z 25 PC: 2b853 | Get default drive
2018-12-17T22:24:44.71832439Z 37 PC: 2b313 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:24:44.719390596Z 37 PC: 2b31a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:24:44.720451158Z 37 PC: 2b321 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:44.724894824Z 74 PC: 2a4bc | Reallocate memory
2018-12-17T22:24:44.725917024Z 72 PC: 2a4fd | Allocate memory
2018-12-17T22:24:44.727065644Z 72 PC: 2a535 | Allocate memory
2018-12-17T22:24:44.7289074Z 72 PC: 2a53d | Allocate memory