Sample viewer

vx.netlux.org/Trojan.DOS.HeyChris

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:26.634461075Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:43:26.637125557Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:26.638501383Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:26.64014071Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:43:26.641716966Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:43:26.64312812Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:26.644145963Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:43:26.64550349Z 68 PC: 12e59 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:43:26.647214949Z 68 PC: 12e59 | I/O control for devices (Set for = '')
2018-12-17T22:43:26.648508361Z 28 PC: 12dce | Get allocation info for specified drive
2018-12-17T22:43:27.017076903Z 37 PC: 12c36 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:27.019560113Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:27.021370441Z 37 PC: 12c4c | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:43:27.02309735Z 37 PC: 12c57 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:43:27.028612545Z 76 PC: 12be0 | Terminate with return code (Return code = '0')