Sample viewer

vx.netlux.org/Trojan.DOS.A4F-Spoof

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:29.871769571Z 74 PC: 12a8f | Reallocate memory
2018-12-17T22:41:29.874281619Z 41 PC: 12af6 | Parse filename
2018-12-17T22:41:29.876690744Z 41 PC: 12afe | Parse filename
2018-12-17T22:41:29.878441232Z 75 PC: 12b1a | Execute program
2018-12-17T22:41:29.903343914Z 80 PC: 14b19 | Set current PSP
2018-12-17T22:41:29.905121533Z 48 PC: 14b1e | Get DOS version
2018-12-17T22:41:29.906630176Z 99 PC: 1b300 | Get DBCS lead byte table pointer
2018-12-17T22:41:29.90874601Z 101 PC: 14ba4 | Get extended country info
2018-12-17T22:41:29.910501137Z 99 PC: 14baa | Get DBCS lead byte table pointer
2018-12-17T22:41:29.911670563Z 74 PC: 14c0c | Reallocate memory
2018-12-17T22:41:29.912902838Z 25 PC: 14c43 | Get default drive
2018-12-17T22:41:29.915298778Z 37 PC: 14703 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:41:29.916456723Z 37 PC: 1470a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:29.918028265Z 37 PC: 14711 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:29.92202438Z 74 PC: 138ac | Reallocate memory
2018-12-17T22:41:29.923468142Z 72 PC: 138ed | Allocate memory
2018-12-17T22:41:29.925081943Z 72 PC: 13925 | Allocate memory
2018-12-17T22:41:29.927257218Z 72 PC: 1392d | Allocate memory