Sample viewer

vx.netlux.org/Trojan.DOS.A_Check

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:23.429884735Z 48 PC: 12a4c | Get DOS version
2018-12-17T21:58:23.431475875Z 53 PC: 12bbe | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:23.432878741Z 53 PC: 12bcb | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:58:23.434548168Z 53 PC: 12bd8 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:58:23.436659485Z 53 PC: 12be5 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:58:23.438116379Z 37 PC: 12bf9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:58:23.439891011Z 74 PC: 12adb | Reallocate memory
2018-12-17T21:58:23.44191363Z 68 PC: 12f4d | I/O control for devices (Set for = '')
2018-12-17T21:58:23.444226561Z 74 PC: 14491 | Reallocate memory
2018-12-17T21:58:23.461856916Z 74 PC: 14491 | Reallocate memory
2018-12-17T21:58:23.464468061Z 68 PC: 12f4d | I/O control for devices
2018-12-17T21:58:23.469346027Z 55 PC: 14570 | Get or set switch character
2018-12-17T21:58:23.472848252Z 41 PC: 14dc0 | Parse filename
2018-12-17T21:58:23.474821524Z 41 PC: 14ddf | Parse filename
2018-12-17T21:58:23.47665579Z 75 PC: 14e22 | Execute program
2018-12-17T21:58:23.496946355Z 80 PC: 1d029 | Set current PSP
2018-12-17T21:58:23.498181713Z 48 PC: 1d02e | Get DOS version
2018-12-17T21:58:23.50050771Z 99 PC: 23810 | Get DBCS lead byte table pointer
2018-12-17T21:58:23.504025672Z 101 PC: 1d0b4 | Get extended country info
2018-12-17T21:58:23.509309569Z 99 PC: 1d0ba | Get DBCS lead byte table pointer
2018-12-17T21:58:23.513683705Z 74 PC: 1d11c | Reallocate memory
2018-12-17T21:58:23.517220989Z 25 PC: 1d153 | Get default drive
2018-12-17T21:58:23.522613777Z 37 PC: 1cc13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:58:23.523734078Z 37 PC: 1cc1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:23.524823994Z 37 PC: 1cc21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:23.53077789Z 74 PC: 1bdbc | Reallocate memory
2018-12-17T21:58:23.532336684Z 72 PC: 1bdfd | Allocate memory
2018-12-17T21:58:23.535639772Z 72 PC: 1be35 | Allocate memory
2018-12-17T21:58:23.538655589Z 72 PC: 1be3d | Allocate memory