Sample viewer

vx.netlux.org/Trojan.DOS.H-Toys

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:08.830175899Z 48 PC: 2277e | Get DOS version
2018-12-17T22:28:08.831567583Z 74 PC: 12b06 | Reallocate memory
2018-12-17T22:28:08.836733238Z 60 PC: 12bbb | Create or truncate file
2018-12-17T22:28:08.841594338Z 69 PC: 12bd9 | Duplicate handle
2018-12-17T22:28:08.851774088Z 70 PC: 12be4 | Redirect handle
2018-12-17T22:28:08.85482519Z 41 PC: 12c45 | Parse filename
2018-12-17T22:28:08.856492504Z 41 PC: 12c4d | Parse filename
2018-12-17T22:28:08.858206795Z 75 PC: 12c69 | Execute program
2018-12-17T22:28:08.879553196Z 80 PC: 148e9 | Set current PSP
2018-12-17T22:28:08.880659754Z 48 PC: 148ee | Get DOS version
2018-12-17T22:28:08.88243562Z 99 PC: 1b0d0 | Get DBCS lead byte table pointer
2018-12-17T22:28:08.894092498Z 101 PC: 14974 | Get extended country info
2018-12-17T22:28:08.895813868Z 99 PC: 1497a | Get DBCS lead byte table pointer
2018-12-17T22:28:08.897294999Z 74 PC: 149dc | Reallocate memory
2018-12-17T22:28:08.899394485Z 25 PC: 14a13 | Get default drive
2018-12-17T22:28:08.900644503Z 37 PC: 144d3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:28:08.901761884Z 37 PC: 144da | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:28:08.904116399Z 37 PC: 144e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:28:08.911698957Z 74 PC: 1367c | Reallocate memory
2018-12-17T22:28:08.913159095Z 72 PC: 136bd | Allocate memory
2018-12-17T22:28:08.915033049Z 72 PC: 136f5 | Allocate memory
2018-12-17T22:28:08.917085758Z 72 PC: 136fd | Allocate memory