Sample viewer

vx.netlux.org/Trojan.DOS.ProvRout

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:36.844815685Z 74 PC: 16dfb | Reallocate memory
2018-12-17T22:43:36.852057681Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:43:36.85315506Z 53 PC: 12bc3 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:36.854192247Z 53 PC: 12bd0 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:36.855887801Z 53 PC: 12bdd | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:43:36.857177726Z 53 PC: 12bea | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:43:36.858428659Z 37 PC: 12bfe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:36.860139882Z 74 PC: 12ad9 | Reallocate memory
2018-12-17T22:43:36.862875972Z 68 PC: 12f7d | I/O control for devices (Set for = '')
2018-12-17T22:43:36.866049012Z 74 PC: 14901 | Reallocate memory
2018-12-17T22:43:36.86872832Z 68 PC: 12f7d | I/O control for devices (Set for = 'Borland C++ - Copyright 1991 Borland Intl.')
2018-12-17T22:43:36.875206223Z 74 PC: 14901 | Reallocate memory
2018-12-17T22:43:36.8833126Z 74 PC: 14901 | Reallocate memory
2018-12-17T22:43:36.885402067Z 74 PC: 14901 | Reallocate memory
2018-12-17T22:43:36.89057157Z 74 PC: 14901 | Reallocate memory
2018-12-17T22:43:36.893546869Z 37 PC: 12c0a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:36.894727932Z 37 PC: 12c15 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:36.895856558Z 37 PC: 12c20 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:43:36.897528009Z 37 PC: 12c2b | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:43:36.899235624Z 76 PC: 12bb4 | Terminate with return code (Return code = '1')