Sample viewer

vx.netlux.org/Trojan.DOS.Nogzoeen

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:53.208778895Z 74 PC: 12cc7 | Reallocate memory
2018-12-17T22:42:53.210658251Z 26 PC: 12cdb | Set disk transfer address
2018-12-17T22:42:53.213925395Z 75 PC: 12ebe | Execute program
2018-12-17T22:42:53.219004307Z 75 PC: 12ef1 | Execute program
2018-12-17T22:42:53.224654358Z 75 PC: 12ebe | Execute program
2018-12-17T22:42:53.228990194Z 75 PC: 12ef1 | Execute program
2018-12-17T22:42:53.233864358Z 75 PC: 12d40 | Execute program
2018-12-17T22:42:53.255000264Z 80 PC: 15109 | Set current PSP
2018-12-17T22:42:53.256063057Z 48 PC: 1510e | Get DOS version
2018-12-17T22:42:53.257739598Z 99 PC: 1b8f0 | Get DBCS lead byte table pointer
2018-12-17T22:42:53.268179982Z 101 PC: 15194 | Get extended country info
2018-12-17T22:42:53.269728585Z 99 PC: 1519a | Get DBCS lead byte table pointer
2018-12-17T22:42:53.271236979Z 74 PC: 151fc | Reallocate memory
2018-12-17T22:42:53.272910239Z 25 PC: 15233 | Get default drive
2018-12-17T22:42:53.275000311Z 37 PC: 14cf3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:42:53.276153553Z 37 PC: 14cfa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:42:53.277370733Z 37 PC: 14d01 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:53.289703903Z 74 PC: 13e9c | Reallocate memory
2018-12-17T22:42:53.291012211Z 72 PC: 13edd | Allocate memory
2018-12-17T22:42:53.292336375Z 72 PC: 13f15 | Allocate memory
2018-12-17T22:42:53.294391985Z 72 PC: 13f1d | Allocate memory