Sample viewer

vx.netlux.org/Trojan.DOS.Lozilka

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:59.455349202Z 48 PC: 13161 | Get DOS version
2018-12-17T21:57:59.458539384Z 53 PC: 1435a | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:57:59.460683742Z 74 PC: 12d49 | Reallocate memory
2018-12-17T21:57:59.462636357Z 74 PC: 12d4d | Reallocate memory
2018-12-17T21:57:59.467188014Z 37 PC: 15ce3 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:57:59.472136446Z 74 PC: 18604 | Reallocate memory
2018-12-17T21:57:59.475017358Z 75 PC: 1859c | Execute program
2018-12-17T21:57:59.497787721Z 80 PC: 2c689 | Set current PSP
2018-12-17T21:57:59.499188173Z 48 PC: 2c68e | Get DOS version
2018-12-17T21:57:59.501210986Z 99 PC: 32e70 | Get DBCS lead byte table pointer
2018-12-17T21:57:59.504644276Z 101 PC: 2c714 | Get extended country info
2018-12-17T21:57:59.507106947Z 99 PC: 2c71a | Get DBCS lead byte table pointer
2018-12-17T21:57:59.508640386Z 74 PC: 2c77c | Reallocate memory
2018-12-17T21:57:59.510399914Z 25 PC: 2c7b3 | Get default drive
2018-12-17T21:57:59.512884812Z 37 PC: 2c273 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:57:59.514314557Z 37 PC: 2c27a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:57:59.51576517Z 37 PC: 2c281 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:59.521142835Z 74 PC: 2b41c | Reallocate memory
2018-12-17T21:57:59.522882762Z 72 PC: 2b45d | Allocate memory
2018-12-17T21:57:59.524795438Z 72 PC: 2b495 | Allocate memory
2018-12-17T21:57:59.538945144Z 72 PC: 2b49d | Allocate memory