Sample viewer

vx.netlux.org/Trojan.DOS.Alporon

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:53.531047892Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:24:53.533102421Z 53 PC: 12bc3 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:53.5352334Z 53 PC: 12bd0 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:24:53.537077056Z 53 PC: 12bdd | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:24:53.542511051Z 53 PC: 12bea | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:24:53.544250799Z 37 PC: 12bfe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:24:53.545408368Z 74 PC: 12ad9 | Reallocate memory
2018-12-17T22:24:53.547559567Z 68 PC: 12e88 | I/O control for devices (Set for = '')
2018-12-17T22:24:53.549750855Z 74 PC: 14380 | Reallocate memory
2018-12-17T22:24:53.551687545Z 74 PC: 14380 | Reallocate memory
2018-12-17T22:24:53.553681945Z 68 PC: 12e88 | I/O control for devices (Set for = 'Borland C++ - Copyright 1991 Borland Intl.')
2018-12-17T22:24:53.556193865Z 65 PC: 12f85 | Delete file (Filename = 'c:\autoexec.bat')
2018-12-17T22:24:53.896799943Z 65 PC: 12f85 | Delete file (Filename = 'c:\autoexec.bak')
2018-12-17T22:24:53.902405316Z 65 PC: 12f85 | Delete file (Filename = 'c:\autoexec.nav')
2018-12-17T22:24:53.909417372Z 65 PC: 12f85 | Delete file (Filename = 'c:\autoexec.dos')
2018-12-17T22:24:53.914993232Z 65 PC: 12f85 | Delete file (Filename = 'c:\autoexec.dos')
2018-12-17T22:24:53.920536438Z 65 PC: 12f85 | Delete file (Filename = 'c:\command.com')
2018-12-17T22:24:53.932286Z 65 PC: 12f85 | Delete file (Filename = 'c:\config.sys')
2018-12-17T22:24:53.943220484Z 65 PC: 12f85 | Delete file (Filename = 'c:\config.dos')
2018-12-17T22:24:53.949072222Z 65 PC: 12f85 | Delete file (Filename = 'c:\config.bak')
2018-12-17T22:24:53.957837516Z 7 PC: 13e60 | Direct console input without echo