Sample viewer

vx.netlux.org/Trojan.DOS.Dopewar.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:07:53.272967713Z 48 PC: 182dc | Get DOS version
2018-12-17T22:07:53.274176462Z 74 PC: 1832c | Reallocate memory
2018-12-17T22:07:53.275995358Z 48 PC: 18390 | Get DOS version
2018-12-17T22:07:53.277831727Z 53 PC: 18398 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:07:53.27871892Z 37 PC: 183aa | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:07:53.279755275Z 53 PC: 1b192 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:07:53.281210214Z 37 PC: 1b1a2 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:07:53.282068774Z 53 PC: 1b1a7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:07:53.283087566Z 37 PC: 1b1b7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:07:53.284559772Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:07:53.285633956Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:07:53.286651422Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:07:53.288122273Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:07:53.288920928Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:07:53.289787161Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:07:53.291526916Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:07:53.292418013Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:07:53.293279433Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:07:53.295207919Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:07:53.296178946Z 53 PC: 18ee6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:07:53.297201596Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:07:53.298659395Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:07:53.299770477Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:07:53.300914841Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:07:53.302253432Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:07:53.303420853Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:07:53.30462659Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:07:53.306239293Z 37 PC: 18f15 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:07:53.307178711Z 37 PC: 18f1c | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:07:53.308094758Z 37 PC: 18f21 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:07:53.309760402Z 68 PC: 1843b | I/O control for devices (Set for = '_^UFV x')
2018-12-17T22:07:53.311294056Z 68 PC: 1843b | I/O control for devices (Set for = '')
2018-12-17T22:07:53.312640706Z 68 PC: 1843b | I/O control for devices (Set for = 'DD 3rD\l|3?I|at+@}[0~ t 3߃0s t&')
2018-12-17T22:07:53.314317036Z 68 PC: 1843b | I/O control for devices (Set for = 'rD\l|3?I|at+@}[0~ t 3߃0s t&')
2018-12-17T22:07:53.315342592Z 68 PC: 1843b | I/O control for devices (Set for = 'rD\l|3?I|at+@}[0~ t 3߃0s t&')
2018-12-17T22:07:53.31718404Z 53 PC: 15634 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:07:53.318523267Z 53 PC: 15641 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:07:53.319582747Z 53 PC: 1564e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:07:53.320831367Z 37 PC: 15663 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:07:53.322108704Z 37 PC: 1566b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:07:53.323307717Z 37 PC: 15673 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:07:53.32441956Z 53 PC: 160f2 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:07:53.325747293Z 53 PC: 160ff | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:07:53.326999113Z 53 PC: 1610e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:07:53.327779791Z 37 PC: 1611b | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:07:53.328883077Z 53 PC: 16122 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:07:53.329822808Z 37 PC: 1612f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:07:53.330774721Z 53 PC: 1613b | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:07:53.334841956Z 48 PC: 161fd | Get DOS version
2018-12-17T22:07:53.336003351Z 74 PC: 1408f | Reallocate memory
2018-12-17T22:07:53.33782465Z 74 PC: 1408f | Reallocate memory
2018-12-17T22:07:53.339509316Z 68 PC: 155aa | I/O control for devices (Set for = 'hitty day! ')
2018-12-17T22:07:53.34064472Z 68 PC: 155aa | I/O control for devices (Set for = '')
2018-12-17T22:07:53.341574059Z 51 PC: 155c8 | Get or set Ctrl-Break
2018-12-17T22:07:53.342786284Z 51 PC: 155d4 | Get or set Ctrl-Break
2018-12-17T22:07:53.343796589Z 72 PC: 12f28 | Allocate memory
2018-12-17T22:07:53.345439988Z 74 PC: 1408f | Reallocate memory
2018-12-17T22:07:53.346633906Z 72 PC: 12f28 | Allocate memory
2018-12-17T22:07:53.348242589Z 37 PC: 133b9 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:07:53.354664797Z 73 PC: 12f28 | Release memory
2018-12-17T22:07:53.358915638Z 74 PC: 1408f | Reallocate memory
2018-12-17T22:07:53.36032635Z 51 PC: 155df | Get or set Ctrl-Break
2018-12-17T22:07:53.361383904Z 53 PC: 13abc | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:07:53.362597849Z 53 PC: 13ac9 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:07:53.363679656Z 53 PC: 13ad6 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:07:53.364894435Z 37 PC: 13af1 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:07:53.366078818Z 53 PC: 13af9 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:07:53.367236143Z 37 PC: 13b06 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:07:53.36859111Z 53 PC: 13b0d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:07:53.369644946Z 37 PC: 13b1a | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:07:53.370828809Z 37 PC: 13b24 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:07:53.372278551Z 37 PC: 13b2f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:07:53.373410561Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:07:53.374361943Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:07:53.375935991Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:07:53.377061945Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:07:53.378032421Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:07:53.379567805Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:07:53.38068517Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:07:53.381635172Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:07:53.383172801Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:07:53.384216072Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:07:53.385463427Z 37 PC: 18f31 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:07:53.387203863Z 37 PC: 1b1c6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:07:53.388567814Z 37 PC: 184ec | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:07:53.390728484Z 41 PC: 181d5 | Parse filename
2018-12-17T22:07:53.392614509Z 41 PC: 181d7 | Parse filename
2018-12-17T22:07:53.394319166Z 41 PC: 181dc | Parse filename
2018-12-17T22:07:53.396119103Z 75 PC: 181f2 | Execute program
2018-12-17T22:07:53.416412323Z 80 PC: 1e349 | Set current PSP
2018-12-17T22:07:53.417099356Z 48 PC: 1e34e | Get DOS version
2018-12-17T22:07:53.419884047Z 99 PC: 24b30 | Get DBCS lead byte table pointer
2018-12-17T22:07:53.42258539Z 101 PC: 1e3d4 | Get extended country info
2018-12-17T22:07:53.423866732Z 99 PC: 1e3da | Get DBCS lead byte table pointer
2018-12-17T22:07:53.425424452Z 74 PC: 1e43c | Reallocate memory
2018-12-17T22:07:53.42666732Z 25 PC: 1e473 | Get default drive
2018-12-17T22:07:53.427498286Z 37 PC: 1df33 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:07:53.428744899Z 37 PC: 1df3a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:07:53.429983813Z 37 PC: 1df41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:07:53.434309125Z 74 PC: 1d0dc | Reallocate memory
2018-12-17T22:07:53.43704956Z 72 PC: 1d11d | Allocate memory
2018-12-17T22:07:53.438734654Z 72 PC: 1d155 | Allocate memory
2018-12-17T22:07:53.441009303Z 72 PC: 1d15d | Allocate memory