Sample viewer

vx.netlux.org/Trojan.DOS.NetPatch

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:40.707593337Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:25:40.710323652Z 41 PC: 12aba | Parse filename
2018-12-17T22:25:40.712200504Z 41 PC: 12ac2 | Parse filename
2018-12-17T22:25:40.713872284Z 75 PC: 12ade | Execute program
2018-12-17T22:25:40.73835674Z 80 PC: 14989 | Set current PSP
2018-12-17T22:25:40.740611294Z 48 PC: 1498e | Get DOS version
2018-12-17T22:25:40.742452824Z 99 PC: 1b170 | Get DBCS lead byte table pointer
2018-12-17T22:25:40.745883477Z 101 PC: 14a14 | Get extended country info
2018-12-17T22:25:40.748469233Z 99 PC: 14a1a | Get DBCS lead byte table pointer
2018-12-17T22:25:40.750344606Z 74 PC: 14a7c | Reallocate memory
2018-12-17T22:25:40.752367955Z 25 PC: 14ab3 | Get default drive
2018-12-17T22:25:40.755353561Z 37 PC: 14573 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:25:40.757147681Z 37 PC: 1457a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:25:40.758869223Z 37 PC: 14581 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:40.764618884Z 74 PC: 1371c | Reallocate memory
2018-12-17T22:25:40.766864878Z 72 PC: 1375d | Allocate memory
2018-12-17T22:25:40.769037003Z 72 PC: 13795 | Allocate memory
2018-12-17T22:25:40.771367415Z 72 PC: 1379d | Allocate memory