Sample viewer

vx.netlux.org/Trojan.DOS.KillMBR.d

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:32.568224072Z 44 PC: 139b7 | Get time 0x139b7: mov byte ptr [0x424], cl
0x139bb: mov word ptr [0x425], dx
0x139bf: mov ax, ds
0x139c1: mov word ptr [0x43a], ax
0x139c4: mov word ptr [0x43e], ax
0x139c7: mov word ptr [0x436], ax
0x139ca: push ax
0x139cb: mov ax, word ptr [2]
0x139ce: mov word ptr [0xdf3], ax
0x139d1: pop ax
0x139d2: call 0x14851
0x139d5: push es
0x139d6: call 0x16522
0x139d9: pop es
0x139da: mov di, 0x80
0x139dd: mov cl, byte ptr [di]
0x139df: inc di
0x139e0: mov ch, 0
0x139e2: jcxz 0x13a0b
0x139e4: cld
2018-12-17T22:54:32.573183108Z 81 PC: 1652c | Get current PSP
2018-12-17T22:54:32.574306659Z 61 PC: 16585 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:54:32.580693049Z 66 PC: 165f0 | Move file pointer
2018-12-17T22:54:32.582641509Z 63 PC: 16608 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:54:32.58542192Z 66 PC: 16693 | Move file pointer
2018-12-17T22:54:32.586677646Z 63 PC: 1669e | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:54:32.594042236Z 63 PC: 16702 | Read file or device (Read 4367 bytes on handle 5)
2018-12-17T22:54:32.600884701Z 62 PC: 1659b | Close file
2018-12-17T22:54:32.603146373Z 48 PC: 167bb | Get DOS version
2018-12-17T22:54:32.60552199Z 74 PC: 13a2e | Reallocate memory
2018-12-17T22:54:32.607509064Z 53 PC: 13eba | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:32.608980888Z 37 PC: 13eca | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:32.611189314Z 82 PC: 13ecf | Get DOS internal pointers (SYSVARS)
2018-12-17T22:54:32.612445036Z 68 PC: 13f11 | I/O control for devices (Set for = '���$5�!�7�9�q�$%�!�')
2018-12-17T22:54:32.613565548Z 68 PC: 13f2a | I/O control for devices (Set for = '���s� ')
2018-12-17T22:54:32.616372231Z 115 PC: 13f43 | UNKNOWN!
2018-12-17T22:54:32.617826313Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.620547679Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.621742392Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.623454462Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.624766959Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.625931813Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.627693942Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.628855601Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.629859059Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.631519105Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.632651448Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.633688138Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.635386012Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.636970098Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.638632209Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.640518428Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.642062429Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.643565158Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.646362406Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.648539903Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.650039323Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.652465922Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.654503624Z 68 PC: 13f11 | I/O control for devices (Set for = '')
2018-12-17T22:54:32.656013868Z 37 PC: 14108 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:32.657955255Z 67 PC: 12c94 | Get or set file attributes
2018-12-17T22:54:32.664252392Z 48 PC: 1474a | Get DOS version
2018-12-17T22:54:32.666186995Z 9 PC: 13e1c | Display string (String= 'This version of Windows does not run on MS-DOS 7.00 or earlier. ')
2018-12-17T22:54:32.675493325Z 76 PC: 13e10 | Terminate with return code (Return code = '255')