Sample viewer

vx.netlux.org/Trojan.DOS.FormatC.e

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:39.97264669Z 74 PC: 12a53 | Reallocate memory
2018-12-17T21:58:39.97465445Z 41 PC: 12aba | Parse filename
2018-12-17T21:58:39.975998278Z 41 PC: 12ac2 | Parse filename
2018-12-17T21:58:39.977406737Z 75 PC: 12add | Execute program
2018-12-17T21:58:40.01350826Z 80 PC: 14c89 | Set current PSP
2018-12-17T21:58:40.014274409Z 48 PC: 14c8e | Get DOS version
2018-12-17T21:58:40.015618873Z 99 PC: 1b470 | Get DBCS lead byte table pointer
2018-12-17T21:58:40.018715584Z 101 PC: 14d14 | Get extended country info
2018-12-17T21:58:40.019997444Z 99 PC: 14d1a | Get DBCS lead byte table pointer
2018-12-17T21:58:40.021128164Z 74 PC: 14d7c | Reallocate memory
2018-12-17T21:58:40.02306803Z 25 PC: 14db3 | Get default drive
2018-12-17T21:58:40.024043883Z 37 PC: 14873 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:58:40.024998124Z 37 PC: 1487a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:58:40.027336979Z 37 PC: 14881 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:58:40.031464238Z 74 PC: 13a1c | Reallocate memory
2018-12-17T21:58:40.032708962Z 72 PC: 13a5d | Allocate memory
2018-12-17T21:58:40.042333783Z 72 PC: 13a95 | Allocate memory
2018-12-17T21:58:40.043904585Z 72 PC: 13a9d | Allocate memory