Sample viewer

vx.netlux.org/Trojan.DOS.Andromeda

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:25.013211757Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:49:25.015664004Z 53 PC: 12bf2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:25.017266785Z 53 PC: 12bff | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:49:25.018816638Z 53 PC: 12c0c | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:49:25.031317144Z 53 PC: 12c19 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:49:25.032768871Z 37 PC: 12c2d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:25.042405417Z 74 PC: 12af7 | Reallocate memory
2018-12-17T22:49:25.045957411Z 68 PC: 12f88 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:49:25.048456065Z 68 PC: 12f88 | I/O control for devices (Set for = '')
2018-12-17T22:49:25.053697372Z 64 PC: 14b1b | Write file or device (Write 48 bytes on handle 1)
2018-12-17T22:49:25.061242217Z 37 PC: 12c39 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:49:25.064174066Z 37 PC: 12c44 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:49:25.065799019Z 37 PC: 12c4f | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:49:25.068071519Z 37 PC: 12c5a | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:49:25.070095752Z 76 PC: 12be3 | Terminate with return code (Return code = '1')