Sample viewer

vx.netlux.org/Trojan.DOS.DosVir

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:46.879542399Z 74 PC: 12a52 | Reallocate memory
2018-12-17T22:48:46.882048357Z 75 PC: 12aa7 | Execute program
2018-12-17T22:48:46.906753226Z 80 PC: 15229 | Set current PSP
2018-12-17T22:48:46.907830921Z 48 PC: 1522e | Get DOS version
2018-12-17T22:48:46.909689504Z 99 PC: 1ba10 | Get DBCS lead byte table pointer
2018-12-17T22:48:46.914208263Z 101 PC: 152b4 | Get extended country info
2018-12-17T22:48:46.916114716Z 99 PC: 152ba | Get DBCS lead byte table pointer
2018-12-17T22:48:46.918258884Z 74 PC: 1531c | Reallocate memory
2018-12-17T22:48:46.921153272Z 25 PC: 15353 | Get default drive
2018-12-17T22:48:46.922962933Z 37 PC: 14e13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:48:46.92484036Z 37 PC: 14e1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:48:46.927316453Z 37 PC: 14e21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:46.932709947Z 74 PC: 13fbc | Reallocate memory
2018-12-17T22:48:46.935001613Z 72 PC: 13ffd | Allocate memory
2018-12-17T22:48:46.93822522Z 72 PC: 14035 | Allocate memory
2018-12-17T22:48:46.940923609Z 72 PC: 1403d | Allocate memory