Sample viewer

vx.netlux.org/Trojan.DOS.FormatC.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:15.088734303Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:26:15.090806304Z 48 PC: 12bba | Get DOS version
2018-12-17T22:26:15.091900947Z 82 PC: 12bc3 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:26:15.093463345Z 71 PC: 12d0f | Get current directory
2018-12-17T22:26:15.09684211Z 26 PC: 12eeb | Set disk transfer address
2018-12-17T22:26:15.098638412Z 78 PC: 12ef3 | Find first file
2018-12-17T22:26:15.10396989Z 26 PC: 12eeb | Set disk transfer address
2018-12-17T22:26:15.105170098Z 78 PC: 12ef3 | Find first file
2018-12-17T22:26:15.110173344Z 26 PC: 12eeb | Set disk transfer address
2018-12-17T22:26:15.111093216Z 78 PC: 12ef3 | Find first file
2018-12-17T22:26:15.115918696Z 26 PC: 12eeb | Set disk transfer address
2018-12-17T22:26:15.117237865Z 78 PC: 12ef3 | Find first file
2018-12-17T22:26:15.129666554Z 41 PC: 12e47 | Parse filename
2018-12-17T22:26:15.131399048Z 41 PC: 12e4f | Parse filename
2018-12-17T22:26:15.133337805Z 75 PC: 12e6a | Execute program
2018-12-17T22:26:15.148289844Z 98 PC: 179a0 | Get current PSP
2018-12-17T22:26:15.149178875Z 99 PC: 15574 | Get DBCS lead byte table pointer
2018-12-17T22:26:15.150528282Z 68 PC: 1558e | I/O control for devices (Set for = '')
2018-12-17T22:26:15.151492741Z 68 PC: 15599 | I/O control for devices (Set for = '')
2018-12-17T22:26:15.152519804Z 68 PC: 155a4 | I/O control for devices (Set for = '')
2018-12-17T22:26:15.15379371Z 68 PC: 155ac | I/O control for devices (Set for = 'bgtS3[r2W<t<u6u>>W')
2018-12-17T22:26:15.155074148Z 48 PC: 155b1 | Get DOS version
2018-12-17T22:26:15.156348146Z 99 PC: 17958 | Get DBCS lead byte table pointer
2018-12-17T22:26:15.158482863Z 68 PC: 17f53 | I/O control for devices (Set for = '')
2018-12-17T22:26:15.160158969Z 68 PC: 1974a | I/O control for devices (Set for = '')
2018-12-17T22:26:15.161742404Z 25 PC: 17e40 | Get default drive
2018-12-17T22:26:15.1632606Z 68 PC: 17e57 | I/O control for devices (Set for = '')
2018-12-17T22:26:15.166019273Z 68 PC: 17e7b | I/O control for devices (Set for = '')
2018-12-17T22:26:15.16792844Z 96 PC: 17eb4 | Qualify filename
2018-12-17T22:26:15.171666402Z 37 PC: 17ed6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:26:15.17326597Z 74 PC: 1826e | Reallocate memory
2018-12-17T22:26:15.17497053Z 68 PC: 1974a | I/O control for devices (Set for = '')
2018-12-17T22:26:15.178261239Z 72 PC: 1976e | Allocate memory
2018-12-17T22:26:15.179800731Z 72 PC: 197b1 | Allocate memory
2018-12-17T22:26:15.181285028Z 72 PC: 197cf | Allocate memory
2018-12-17T22:26:15.185463776Z 72 PC: 197ed | Allocate memory
2018-12-17T22:26:15.187020029Z 72 PC: 19802 | Allocate memory
2018-12-17T22:26:15.188890247Z 72 PC: 1981f | Allocate memory
2018-12-17T22:26:15.19257367Z 64 PC: 156e6 | Write file or device (Write 49 bytes on handle 1)
2018-12-17T22:26:15.198801703Z 64 PC: 156b6 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:26:15.201952568Z 64 PC: 156e6 | Write file or device (Write 43 bytes on handle 1)
2018-12-17T22:26:15.208089959Z 12 PC: 18cb6 | Flush input buffer and input
2018-12-17T22:26:15.215862473Z 10 PC: 18cbd | Buffered keyboard input