Sample viewer

vx.netlux.org/Trojan.DOS.Opera

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:18.168540774Z 48 PC: 179cc | Get DOS version
2018-12-17T22:10:18.170306375Z 74 PC: 17a1c | Reallocate memory
2018-12-17T22:10:18.171675847Z 48 PC: 17a80 | Get DOS version
2018-12-17T22:10:18.186137438Z 53 PC: 17a88 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:18.187672284Z 37 PC: 17a9a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:18.188959602Z 53 PC: 1a122 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:10:18.189844498Z 37 PC: 1a132 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:10:18.191522614Z 53 PC: 1a137 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:18.192849855Z 37 PC: 1a147 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:10:18.194266362Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:10:18.195734921Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:10:18.197494182Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:10:18.198941345Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:10:18.199938105Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:10:18.200977052Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:10:18.201959765Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:10:18.203238841Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:10:18.209506376Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:10:18.212838089Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:10:18.21512772Z 53 PC: 17e76 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:10:18.218050495Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:10:18.219481601Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:10:18.220866109Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:10:18.223114682Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:10:18.224223624Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:10:18.22529786Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:10:18.22749513Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:10:18.228907191Z 37 PC: 17ea5 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:10:18.230267664Z 37 PC: 17eac | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:10:18.232291552Z 37 PC: 17eb1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:10:18.233956818Z 68 PC: 17b2b | I/O control for devices (Set for = '')
2018-12-17T22:10:18.235523961Z 68 PC: 17b2b | I/O control for devices
2018-12-17T22:10:18.237766435Z 68 PC: 17b2b | I/O control for devices (Set for = '')
2018-12-17T22:10:18.239152957Z 68 PC: 17b2b | I/O control for devices (Set for = '')
2018-12-17T22:10:18.240438479Z 68 PC: 17b2b | I/O control for devices (Set for = '')
2018-12-17T22:10:18.24324184Z 53 PC: 15728 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:18.244545823Z 53 PC: 15735 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:10:18.246455886Z 53 PC: 15742 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:18.248100796Z 37 PC: 15757 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:10:18.249208753Z 37 PC: 1575f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:10:18.250395034Z 37 PC: 15767 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:10:18.252130607Z 53 PC: 161e6 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:10:18.253350329Z 53 PC: 161f3 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:10:18.254823796Z 53 PC: 16202 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:10:18.256887062Z 37 PC: 1620f | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:10:18.257975632Z 53 PC: 16216 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:10:18.25894673Z 37 PC: 16223 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:10:18.260370372Z 53 PC: 1622f | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:10:18.264416944Z 48 PC: 162f1 | Get DOS version
2018-12-17T22:10:18.265486227Z 74 PC: 143f3 | Reallocate memory
2018-12-17T22:10:18.267068828Z 74 PC: 143f3 | Reallocate memory
2018-12-17T22:10:18.268639915Z 68 PC: 1569e | I/O control for devices (Set for = 'ading :')
2018-12-17T22:10:18.270151091Z 68 PC: 1569e | I/O control for devices (Set for = '')
2018-12-17T22:10:18.272880752Z 51 PC: 156bc | Get or set Ctrl-Break
2018-12-17T22:10:18.274064173Z 51 PC: 156c8 | Get or set Ctrl-Break