Sample viewer

vx.netlux.org/Trojan.DOS.Zebra.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:44.319391401Z 74 PC: 12b06 | Reallocate memory
2018-12-17T22:49:44.32228431Z 61 PC: 12b42 | Open file (Filename = 'log')
2018-12-17T22:49:44.327244972Z 60 PC: 12b49 | Create or truncate file
2018-12-17T22:49:44.341650498Z 66 PC: 12b5a | Move file pointer
2018-12-17T22:49:44.359894826Z 69 PC: 12b67 | Duplicate handle
2018-12-17T22:49:44.362264416Z 70 PC: 12b72 | Redirect handle
2018-12-17T22:49:44.364415412Z 41 PC: 12bd3 | Parse filename
2018-12-17T22:49:44.366477666Z 41 PC: 12bdb | Parse filename
2018-12-17T22:49:44.368537347Z 75 PC: 12bf7 | Execute program
2018-12-17T22:49:44.388802428Z 80 PC: 14c09 | Set current PSP
2018-12-17T22:49:44.389756059Z 48 PC: 14c0e | Get DOS version
2018-12-17T22:49:44.397560299Z 99 PC: 1b3f0 | Get DBCS lead byte table pointer
2018-12-17T22:49:44.400236929Z 101 PC: 14c94 | Get extended country info
2018-12-17T22:49:44.401611308Z 99 PC: 14c9a | Get DBCS lead byte table pointer
2018-12-17T22:49:44.406022889Z 74 PC: 14cfc | Reallocate memory
2018-12-17T22:49:44.407764977Z 25 PC: 14d33 | Get default drive
2018-12-17T22:49:44.409217029Z 37 PC: 147f3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:49:44.411418334Z 37 PC: 147fa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:49:44.413532377Z 37 PC: 14801 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:44.418183081Z 74 PC: 1399c | Reallocate memory
2018-12-17T22:49:44.421246622Z 72 PC: 139dd | Allocate memory
2018-12-17T22:49:44.422857697Z 72 PC: 13a15 | Allocate memory
2018-12-17T22:49:44.424495653Z 72 PC: 13a1d | Allocate memory