Sample viewer

vx.netlux.org/Trojan.DOS.Imitator

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:07.373337884Z 48 PC: 12cd3 | Get DOS version
2018-12-17T22:35:07.375802224Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:35:07.377899351Z 41 PC: 12aba | Parse filename
2018-12-17T22:35:07.378973033Z 41 PC: 12ac2 | Parse filename
2018-12-17T22:35:07.380028157Z 75 PC: 12add | Execute program
2018-12-17T22:35:07.398361143Z 80 PC: 149b9 | Set current PSP
2018-12-17T22:35:07.399302951Z 48 PC: 149be | Get DOS version
2018-12-17T22:35:07.400953798Z 99 PC: 1b1a0 | Get DBCS lead byte table pointer
2018-12-17T22:35:07.404225325Z 101 PC: 14a44 | Get extended country info
2018-12-17T22:35:07.40565978Z 99 PC: 14a4a | Get DBCS lead byte table pointer
2018-12-17T22:35:07.406863349Z 74 PC: 14aac | Reallocate memory
2018-12-17T22:35:07.408527062Z 25 PC: 14ae3 | Get default drive
2018-12-17T22:35:07.41146753Z 37 PC: 145a3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:35:07.412851634Z 37 PC: 145aa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:35:07.41468495Z 37 PC: 145b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:07.420172272Z 74 PC: 1374c | Reallocate memory
2018-12-17T22:35:07.422049476Z 72 PC: 1378d | Allocate memory
2018-12-17T22:35:07.424024132Z 72 PC: 137c5 | Allocate memory
2018-12-17T22:35:07.430147125Z 72 PC: 137cd | Allocate memory