Sample viewer

vx.netlux.org/Trojan.DOS.FZip

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:49.698203994Z 48 PC: 13161 | Get DOS version
2018-12-17T22:31:49.708756109Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:31:49.711380218Z 74 PC: 12d49 | Reallocate memory
2018-12-17T22:31:49.714287232Z 74 PC: 12d4d | Reallocate memory
2018-12-17T22:31:49.718727272Z 37 PC: 15ce3 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:31:49.727091186Z 61 PC: 162d9 | Open file (Filename = '')
2018-12-17T22:31:49.735551155Z 60 PC: 162d9 | Create or truncate file
2018-12-17T22:31:50.15390858Z 66 PC: 162d9 | Move file pointer
2018-12-17T22:31:50.155875604Z 66 PC: 162d9 | Move file pointer
2018-12-17T22:31:50.159875139Z 64 PC: 162d9 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:31:50.170286952Z 64 PC: 162d9 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:31:50.1740576Z 64 PC: 162d9 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:31:50.177870587Z 64 PC: 162d9 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:31:50.181904592Z 64 PC: 162d9 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:31:50.185622223Z 64 PC: 162d9 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:31:50.189801861Z 62 PC: 162d9 | Close file
2018-12-17T22:31:50.200154201Z 74 PC: 18f20 | Reallocate memory
2018-12-17T22:31:50.202894583Z 75 PC: 18eb8 | Execute program
2018-12-17T22:31:50.22615417Z 80 PC: 30189 | Set current PSP
2018-12-17T22:31:50.228605067Z 48 PC: 3018e | Get DOS version
2018-12-17T22:31:50.230732072Z 99 PC: 36970 | Get DBCS lead byte table pointer
2018-12-17T22:31:50.23406764Z 101 PC: 30214 | Get extended country info
2018-12-17T22:31:50.236922059Z 99 PC: 3021a | Get DBCS lead byte table pointer
2018-12-17T22:31:50.239191168Z 74 PC: 3027c | Reallocate memory
2018-12-17T22:31:50.241182334Z 25 PC: 302b3 | Get default drive
2018-12-17T22:31:50.244182281Z 37 PC: 2fd73 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:31:50.245891188Z 37 PC: 2fd7a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:50.247572274Z 37 PC: 2fd81 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:50.253888799Z 74 PC: 2ef1c | Reallocate memory
2018-12-17T22:31:50.256702132Z 72 PC: 2ef5d | Allocate memory
2018-12-17T22:31:50.258893753Z 72 PC: 2ef95 | Allocate memory
2018-12-17T22:31:50.261217521Z 72 PC: 2ef9d | Allocate memory