Sample viewer

vx.netlux.org/Trojan.DOS.BatMan.DeltreeY

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:31.181733936Z 74 PC: 12a8f | Reallocate memory
2018-12-17T22:46:31.185075785Z 41 PC: 12af6 | Parse filename
2018-12-17T22:46:31.188408151Z 41 PC: 12afe | Parse filename
2018-12-17T22:46:31.190338394Z 75 PC: 12b1a | Execute program
2018-12-17T22:46:31.215302472Z 80 PC: 14b19 | Set current PSP
2018-12-17T22:46:31.217126658Z 48 PC: 14b1e | Get DOS version
2018-12-17T22:46:31.219225459Z 99 PC: 1b300 | Get DBCS lead byte table pointer
2018-12-17T22:46:31.222162171Z 101 PC: 14ba4 | Get extended country info
2018-12-17T22:46:31.224070506Z 99 PC: 14baa | Get DBCS lead byte table pointer
2018-12-17T22:46:31.226961848Z 74 PC: 14c0c | Reallocate memory
2018-12-17T22:46:31.229024069Z 25 PC: 14c43 | Get default drive
2018-12-17T22:46:31.231064009Z 37 PC: 14703 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:46:31.233259695Z 37 PC: 1470a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:31.234692958Z 37 PC: 14711 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:31.239687539Z 74 PC: 138ac | Reallocate memory
2018-12-17T22:46:31.246286518Z 72 PC: 138ed | Allocate memory
2018-12-17T22:46:31.248511053Z 72 PC: 13925 | Allocate memory
2018-12-17T22:46:31.25089739Z 72 PC: 1392d | Allocate memory