Sample viewer

vx.netlux.org/Trojan.DOS.Gipeb

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:12.354052182Z 53 PC: 1359a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:12.356191542Z 53 PC: 1359a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:12.358001783Z 53 PC: 1359a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:12.359672922Z 53 PC: 1359a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:12.361696364Z 53 PC: 1359a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:12.364074903Z 53 PC: 1359a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:12.365485454Z 53 PC: 1359a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:12.366900953Z 53 PC: 1359a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:12.368866516Z 53 PC: 1359a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:12.37065151Z 53 PC: 1359a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:12.372438066Z 53 PC: 1359a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:12.376820501Z 53 PC: 1359a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:12.378567653Z 53 PC: 1359a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:12.380261896Z 53 PC: 1359a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:12.383166664Z 53 PC: 1359a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:12.38481985Z 53 PC: 1359a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:12.386122898Z 53 PC: 1359a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:12.388156438Z 53 PC: 1359a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:12.389852655Z 53 PC: 1359a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:12.393115406Z 37 PC: 135af | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:12.395015626Z 37 PC: 135b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:12.396441746Z 37 PC: 135bf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:12.398052492Z 37 PC: 135c7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:12.400321335Z 68 PC: 13f17 | I/O control for devices (Set for = '')
2018-12-17T23:03:12.405212694Z 61 PC: 13efb | Open file (Filename = 'c:\autoexec.bat')
2018-12-17T23:03:12.420326812Z 63 PC: 13961 | Read file or device (Read 128 bytes on handle 5)
2018-12-17T23:03:12.424724495Z 53 PC: 1350a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:12.427219642Z 37 PC: 13513 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:03:12.428656211Z 53 PC: 1350a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:12.430062283Z 37 PC: 13513 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:03:12.432438938Z 53 PC: 1350a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:12.434783313Z 37 PC: 13513 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:03:12.436159178Z 53 PC: 1350a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:12.438556503Z 37 PC: 13513 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:12.440260785Z 53 PC: 1350a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:12.441726248Z 37 PC: 13513 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:12.444728949Z 53 PC: 1350a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:12.448307863Z 37 PC: 13513 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:12.451115559Z 53 PC: 1350a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:12.456140009Z 37 PC: 13513 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:03:12.457671136Z 53 PC: 1350a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:12.459926283Z 37 PC: 13513 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:03:12.462625685Z 53 PC: 1350a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:12.46429937Z 37 PC: 13513 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:03:12.466403243Z 53 PC: 1350a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:12.468540378Z 37 PC: 13513 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:03:12.470434807Z 53 PC: 1350a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:12.471943722Z 37 PC: 13513 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:03:12.473309678Z 53 PC: 1350a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:12.47533869Z 37 PC: 13513 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:03:12.477066567Z 53 PC: 1350a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:12.478831623Z 37 PC: 13513 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:03:12.481043449Z 53 PC: 1350a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:12.482551523Z 37 PC: 13513 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:03:12.484017897Z 53 PC: 1350a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:12.487236965Z 37 PC: 13513 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:03:12.488851859Z 53 PC: 1350a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:12.490210452Z 37 PC: 13513 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:03:12.492398172Z 53 PC: 1350a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:12.493829942Z 37 PC: 13513 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:03:12.495147819Z 53 PC: 1350a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:12.497611378Z 37 PC: 13513 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:03:12.498987243Z 53 PC: 1350a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:12.500406279Z 37 PC: 13513 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:03:12.506428503Z 41 PC: 13459 | Parse filename
2018-12-17T23:03:12.508446154Z 41 PC: 13467 | Parse filename
2018-12-17T23:03:12.510082689Z 75 PC: 13472 | Execute program
2018-12-17T23:03:12.537319372Z 80 PC: 183d9 | Set current PSP
2018-12-17T23:03:12.539152436Z 48 PC: 183de | Get DOS version
2018-12-17T23:03:12.541240199Z 99 PC: 1ebc0 | Get DBCS lead byte table pointer
2018-12-17T23:03:12.544438067Z 101 PC: 18464 | Get extended country info
2018-12-17T23:03:12.546729152Z 99 PC: 1846a | Get DBCS lead byte table pointer
2018-12-17T23:03:12.548144461Z 74 PC: 184cc | Reallocate memory
2018-12-17T23:03:12.549999276Z 25 PC: 18503 | Get default drive
2018-12-17T23:03:12.552782776Z 37 PC: 17fc3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:03:12.554548023Z 37 PC: 17fca | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:12.556256112Z 37 PC: 17fd1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:12.562171135Z 74 PC: 1716c | Reallocate memory
2018-12-17T23:03:12.56459542Z 72 PC: 171ad | Allocate memory
2018-12-17T23:03:12.566722957Z 72 PC: 171e5 | Allocate memory
2018-12-17T23:03:12.569998391Z 72 PC: 171ed | Allocate memory