Sample viewer

vx.netlux.org/Trojan.DOS.Looper

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:19.367727641Z 48 PC: 1651c | Get DOS version
2018-12-17T22:00:19.369896623Z 74 PC: 1656c | Reallocate memory
2018-12-17T22:00:19.371692315Z 48 PC: 165d0 | Get DOS version
2018-12-17T22:00:19.375268941Z 53 PC: 165d8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:19.377467242Z 37 PC: 165ea | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:19.378948914Z 53 PC: 18cc2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:00:19.380170531Z 37 PC: 18cd2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:00:19.381583362Z 53 PC: 18cd7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:00:19.383264468Z 37 PC: 18ce7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:00:19.384250782Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:00:19.385302307Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:00:19.387115181Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:00:19.388299989Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:00:19.389468229Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:00:19.395538986Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:00:19.396978799Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:00:19.398429648Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:00:19.403894833Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:00:19.405201128Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:00:19.406532429Z 53 PC: 16a16 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:00:19.414807674Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:00:19.416955815Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:00:19.418215623Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:00:19.420224254Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:00:19.421148011Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:00:19.429810117Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:00:19.436838207Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:00:19.438006496Z 37 PC: 16a45 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:00:19.439060601Z 37 PC: 16a4c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:00:19.440879425Z 37 PC: 16a51 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:00:19.442221958Z 68 PC: 1667b | I/O control for devices (Set for = 'OO')
2018-12-17T22:00:19.44352343Z 68 PC: 1667b | I/O control for devices
2018-12-17T22:00:19.445661832Z 68 PC: 1667b | I/O control for devices
2018-12-17T22:00:19.446936315Z 68 PC: 1667b | I/O control for devices
2018-12-17T22:00:19.448281248Z 68 PC: 1667b | I/O control for devices
2018-12-17T22:00:19.453551588Z 53 PC: 14a34 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:19.454904537Z 53 PC: 14a41 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:00:19.456194429Z 53 PC: 14a4e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:19.458811769Z 37 PC: 14a63 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:19.460077699Z 37 PC: 14a6b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:00:19.461382196Z 37 PC: 14a73 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:19.463769444Z 53 PC: 154f2 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:00:19.465024467Z 53 PC: 154ff | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:00:19.466302319Z 53 PC: 1550e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:00:19.467996788Z 37 PC: 1551b | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:00:19.469668333Z 53 PC: 15522 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:00:19.470912096Z 37 PC: 1552f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:00:19.472552247Z 53 PC: 1553b | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:00:19.477226093Z 48 PC: 155fd | Get DOS version
2018-12-17T22:00:19.4787172Z 68 PC: 149aa | I/O control for devices (Set for = 'j { N   2 3C')
2018-12-17T22:00:19.480527137Z 68 PC: 149aa | I/O control for devices (Set for = '')
2018-12-17T22:00:19.482499522Z 51 PC: 149c8 | Get or set Ctrl-Break
2018-12-17T22:00:19.483316311Z 51 PC: 149d4 | Get or set Ctrl-Break
2018-12-17T22:00:19.488027903Z 25 PC: 12df8 | Get default drive
2018-12-17T22:00:19.489466066Z 71 PC: 12e08 | Get current directory
2018-12-17T22:00:19.4935301Z 61 PC: 133da | Open file (Filename = 'A:\LOOPER.BAT')
2018-12-17T22:00:19.499521437Z 60 PC: 1329f | Create or truncate file
2018-12-17T22:00:19.850708707Z 62 PC: 1320d | Close file
2018-12-17T22:00:19.852740385Z 61 PC: 133da | Open file (Filename = 'A:\LOOPER.BAT')
2018-12-17T22:00:19.860453048Z 68 PC: 13333 | I/O control for devices (Set for = '  ')
2018-12-17T22:00:19.864393211Z 64 PC: 131fc | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:00:19.866789195Z 64 PC: 131fc | Write file or device (Write 66 bytes on handle 5)
2018-12-17T22:00:19.870889645Z 66 PC: 12faf | Move file pointer
2018-12-17T22:00:19.873514121Z 62 PC: 1320d | Close file
2018-12-17T22:00:19.88177549Z 37 PC: 157cd | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:00:19.883364377Z 53 PC: 157d4 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:00:19.885581278Z 37 PC: 157e1 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:00:19.886640166Z 37 PC: 157ec | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:00:19.88767891Z 37 PC: 157f7 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:00:19.890461303Z 51 PC: 149df | Get or set Ctrl-Break
2018-12-17T22:00:19.891516782Z 37 PC: 14c61 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:19.89303686Z 37 PC: 14c6b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:00:19.894814396Z 37 PC: 14c75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:19.896231418Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:00:19.897444747Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:00:19.898986772Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:00:19.900069463Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:00:19.901100175Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:00:19.902579333Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:00:19.903624933Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:00:19.904717932Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:00:19.906295086Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:00:19.907721911Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:00:19.908795407Z 37 PC: 16a61 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:00:19.910192244Z 37 PC: 18cf6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:00:19.91109814Z 37 PC: 1672c | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:00:19.912603091Z 76 PC: 16715 | Terminate with return code (Return code = '0')