Sample viewer

vx.netlux.org/Trojan.DOS.Snoop

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:25.252591118Z 48 PC: 132ae | Get DOS version
2018-12-17T22:42:25.255266373Z 74 PC: 132ae | Reallocate memory
2018-12-17T22:42:25.360327627Z 61 PC: 132ae | Open file (Filename = 'ys.log')
2018-12-17T22:42:25.367513954Z 60 PC: 132ae | Create or truncate file
2018-12-17T22:42:25.386661617Z 68 PC: 132ae | I/O control for devices (Set for = '')
2018-12-17T22:42:25.388917955Z 44 PC: 157bc | Get time 0x157bc: call 0x238cf
0x157bf: mov ax, word ptr [0x264]
0x157c2: mov al, ah
0x157c4: xor ah, ah
0x157c6: mov word ptr [0x34e], ax
0x157c9: mov ax, word ptr [0x264]
0x157cc: xor ah, ah
0x157ce: mov word ptr [0x350], ax
0x157d1: mov ax, word ptr [0x266]
0x157d4: mov al, ah
0x157d6: xor ah, ah
0x157d8: mov word ptr [0x352], ax
0x157db: mov ax, word ptr [0x266]
0x157de: xor ah, ah
0x157e0: mov word ptr [0x354], ax
0x157e3: mov ax, 0x2a00
0x157e6: mov word ptr [0x260], ax
0x157e9: mov di, 0x260
0x157ec: push ds
0x157ed: call 0x238a7
2018-12-17T22:42:25.392305768Z 42 PC: 157f2 | Get date 0x157f2: call 0x238cf
0x157f5: mov ax, word ptr [0x260]
0x157f8: xor ah, ah
0x157fa: mov word ptr [0x344], ax
0x157fd: mov ax, word ptr [0x264]
0x15800: xor ah, ah
0x15802: mov word ptr [0x346], ax
0x15805: mov ax, word ptr [0x264]
0x15808: mov al, ah
0x1580a: xor ah, ah
0x1580c: mov word ptr [0x348], ax
0x1580f: mov ax, word ptr [0x266]
0x15812: mov al, ah
0x15814: xor ah, ah
0x15816: mov word ptr [0x34a], ax
0x15819: mov ax, word ptr [0x266]
0x1581c: xor ah, ah
0x1581e: mov word ptr [0x34c], ax
0x15821: mov di, 0x274
0x15824: push ds
2018-12-17T22:42:25.396595234Z 64 PC: 132ae | Write file or device (Write 55 bytes on handle 5)
2018-12-17T22:42:25.401164837Z 62 PC: 132ae | Close file