Sample viewer

vx.netlux.org/Trojan.DOS.Paul

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:36.936760377Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:43:36.938889257Z 53 PC: 12b6a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:36.944785322Z 53 PC: 12b77 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:36.947017039Z 53 PC: 12b84 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:43:36.949312772Z 53 PC: 12b91 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:43:36.951000629Z 37 PC: 12ba5 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:36.952048133Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:43:36.954364281Z 74 PC: 13318 | Reallocate memory
2018-12-17T22:43:36.958205214Z 65 PC: 138ca | Delete file (Filename = 'U�M��V�')
2018-12-17T22:43:36.960003749Z 37 PC: 12bb1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:36.961352012Z 37 PC: 12bbc | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:43:36.962691494Z 37 PC: 12bc7 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:43:36.963665724Z 37 PC: 12bd2 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:43:36.96479639Z 76 PC: 12b5a | Terminate with return code (Return code = '0')