Sample viewer

vx.netlux.org/Trojan.DOS.BL

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:49.99260388Z 48 PC: 171ac | Get DOS version
2018-12-17T22:41:49.995069271Z 74 PC: 171fc | Reallocate memory
2018-12-17T22:41:49.997445564Z 48 PC: 17260 | Get DOS version
2018-12-17T22:41:49.998955029Z 53 PC: 17268 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:50.000698684Z 37 PC: 1727a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:50.002493806Z 68 PC: 1730b | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T22:41:50.004070627Z 68 PC: 1730b | I/O control for devices
2018-12-17T22:41:50.005663799Z 68 PC: 1730b | I/O control for devices
2018-12-17T22:41:50.008999575Z 68 PC: 1730b | I/O control for devices
2018-12-17T22:41:50.010651437Z 68 PC: 1730b | I/O control for devices
2018-12-17T22:41:50.012598123Z 53 PC: 14ff8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:50.01490208Z 53 PC: 15005 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:41:50.016285108Z 53 PC: 15012 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:50.017707219Z 37 PC: 15027 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:50.020659034Z 37 PC: 1502f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:41:50.022049145Z 37 PC: 15037 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:50.023529345Z 53 PC: 15ab6 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:41:50.025370973Z 53 PC: 15ac3 | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:41:50.026839592Z 53 PC: 15ad2 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:41:50.028432714Z 37 PC: 15adf | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:41:50.030755797Z 53 PC: 15ae6 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:41:50.032227742Z 37 PC: 15af3 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:41:50.033702141Z 53 PC: 15aff | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:41:50.038006736Z 48 PC: 15bc1 | Get DOS version
2018-12-17T22:41:50.039870005Z 68 PC: 14f6e | I/O control for devices (Set for = '')
2018-12-17T22:41:50.04142707Z 68 PC: 14f6e | I/O control for devices (Set for = '')
2018-12-17T22:41:50.042978754Z 51 PC: 14f8c | Get or set Ctrl-Break
2018-12-17T22:41:50.045222959Z 51 PC: 14f98 | Get or set Ctrl-Break
2018-12-17T22:41:50.047128358Z 37 PC: 13a0d | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:41:50.052393457Z 26 PC: 12be1 | Set disk transfer address
2018-12-17T22:41:50.055098578Z 78 PC: 12be8 | Find first file
2018-12-17T22:41:50.068680577Z 65 PC: 12b5f | Delete file (Filename = 'C:\CONFIG.SYS')
2018-12-17T22:41:50.411374203Z 79 PC: 12b65 | Find next file
2018-12-17T22:41:50.415921915Z 26 PC: 12be1 | Set disk transfer address
2018-12-17T22:41:50.417824117Z 78 PC: 12be8 | Find first file
2018-12-17T22:41:50.423988465Z 65 PC: 12b5f | Delete file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T22:41:50.43509217Z 79 PC: 12b65 | Find next file
2018-12-17T22:41:50.439442842Z 26 PC: 12be1 | Set disk transfer address
2018-12-17T22:41:50.44087946Z 78 PC: 12be8 | Find first file
2018-12-17T22:41:50.44703417Z 65 PC: 12b5f | Delete file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:41:50.459369398Z 79 PC: 12b65 | Find next file
2018-12-17T22:41:50.462504626Z 6 PC: 15f35 | Direct console I/O
2018-12-17T22:41:50.46853367Z 6 PC: 15f35 | Direct console I/O
2018-12-17T22:41:50.474126665Z 6 PC: 15f35 | Direct console I/O
2018-12-17T22:41:50.479685776Z 37 PC: 15d91 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:41:50.481953976Z 53 PC: 15d98 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:41:50.484348273Z 37 PC: 15da5 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:41:50.486680383Z 37 PC: 15db0 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:41:50.488490533Z 37 PC: 15dbb | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:41:50.491174334Z 51 PC: 14fa3 | Get or set Ctrl-Break
2018-12-17T22:41:50.492902129Z 37 PC: 15225 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:50.494447932Z 37 PC: 1522f | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:41:50.496618168Z 37 PC: 15239 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:50.499046309Z 37 PC: 173bc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:41:50.500599085Z 76 PC: 173a5 | Terminate with return code (Return code = '0')