Sample viewer

vx.netlux.org/Trojan.DOS.Delarm.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:49.814898024Z 60 PC: 12a87 | Create or truncate file
2018-12-17T22:45:49.833559726Z 64 PC: 12aa0 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:45:49.838685513Z 64 PC: 12ab2 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.846593599Z 64 PC: 12ac4 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.849729748Z 64 PC: 12b26 | Write file or device (Write 82 bytes on handle 5)
2018-12-17T22:45:49.853485906Z 64 PC: 12b38 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.856614708Z 64 PC: 12b5e | Write file or device (Write 22 bytes on handle 5)
2018-12-17T22:45:49.859672696Z 64 PC: 12b70 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.863956855Z 64 PC: 12b95 | Write file or device (Write 21 bytes on handle 5)
2018-12-17T22:45:49.867121731Z 64 PC: 12ba7 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.870465467Z 64 PC: 12bc4 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:45:49.87496132Z 64 PC: 12bd6 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.878098057Z 64 PC: 12bf5 | Write file or device (Write 15 bytes on handle 5)
2018-12-17T22:45:49.881677646Z 64 PC: 12c07 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.886507202Z 64 PC: 12c26 | Write file or device (Write 15 bytes on handle 5)
2018-12-17T22:45:49.890031625Z 64 PC: 12c38 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:49.898587609Z 64 PC: 12c5d | Write file or device (Write 21 bytes on handle 5)
2018-12-17T22:45:49.901871599Z 62 PC: 12c64 | Close file
2018-12-17T22:45:49.912094803Z 81 PC: 12d42 | Get current PSP
2018-12-17T22:45:49.913030778Z 74 PC: 12d52 | Reallocate memory
2018-12-17T22:45:49.914666351Z 75 PC: 12dc6 | Execute program
2018-12-17T22:45:49.938671472Z 80 PC: 2b729 | Set current PSP
2018-12-17T22:45:49.93990882Z 48 PC: 2b72e | Get DOS version
2018-12-17T22:45:49.941876819Z 99 PC: 31f10 | Get DBCS lead byte table pointer
2018-12-17T22:45:49.94610752Z 101 PC: 2b7b4 | Get extended country info
2018-12-17T22:45:49.948192478Z 99 PC: 2b7ba | Get DBCS lead byte table pointer
2018-12-17T22:45:49.949673167Z 74 PC: 2b81c | Reallocate memory
2018-12-17T22:45:49.952221513Z 25 PC: 2b853 | Get default drive
2018-12-17T22:45:49.953575249Z 37 PC: 2b313 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:45:49.954862734Z 37 PC: 2b31a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:45:49.956365213Z 37 PC: 2b321 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:49.961661546Z 74 PC: 2a4bc | Reallocate memory
2018-12-17T22:45:49.963547143Z 72 PC: 2a4fd | Allocate memory
2018-12-17T22:45:49.965611203Z 72 PC: 2a535 | Allocate memory
2018-12-17T22:45:49.968824843Z 72 PC: 2a53d | Allocate memory