Sample viewer

vx.netlux.org/Trojan.DOS.SPS.102

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:48.789391551Z 52 PC: 12a6d | Get InDOS flag pointer
2018-12-17T22:55:48.791409092Z 81 PC: 12a75 | Get current PSP
2018-12-17T22:55:48.794825454Z 9 PC: 12af9 | Display string (String= ' PasswordCracker 1.02 4 Novell Network. (c) 1997 by Psychomancer aka Nice,SPS.')
2018-12-17T22:55:48.802769435Z 9 PC: 12af9 | Display string (String= ' ')
2018-12-17T22:55:48.806960447Z 37 PC: 12aa8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:48.810114521Z 51 PC: 12dea | Get or set Ctrl-Break
2018-12-17T22:55:48.811612047Z 67 PC: 12e0d | Get or set file attributes
2018-12-17T22:55:48.843175054Z 61 PC: 12e14 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:55:48.851245602Z 64 PC: 12e1f | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:55:48.867967465Z 44 PC: 13bc2 | Get time 0x13bc2: mov ax, 0x3e1
0x13bc5: mul dx
0x13bc7: add ax, cx
0x13bc9: xchg ax, cx
0x13bca: in ax, 0x40
0x13bcc: add ax, cx
0x13bce: mov word ptr [bp + 0xe], ax
0x13bd1: ret
0x13bd2: push bx
0x13bd3: push cx
0x13bd4: push dx
0x13bd5: mov ax, word ptr [bp + 0xe]
0x13bd8: mov cx, 0x3e1
0x13bdb: mul cx
0x13bdd: mov cx, ax
0x13bdf: xor dx, dx
0x13be1: mov bx, 0x35
0x13be4: div bx
0x13be6: add dx, cx
0x13be8: js 0x13bee
2018-12-17T22:55:48.885275553Z 44 PC: 13bc2 | Get time 0x13bc2: mov ax, 0x3e1
0x13bc5: mul dx
0x13bc7: add ax, cx
0x13bc9: xchg ax, cx
0x13bca: in ax, 0x40
0x13bcc: add ax, cx
0x13bce: mov word ptr [bp + 0xe], ax
0x13bd1: ret
0x13bd2: push bx
0x13bd3: push cx
0x13bd4: push dx
0x13bd5: mov ax, word ptr [bp + 0xe]
0x13bd8: mov cx, 0x3e1
0x13bdb: mul cx
0x13bdd: mov cx, ax
0x13bdf: xor dx, dx
0x13be1: mov bx, 0x35
0x13be4: div bx
0x13be6: add dx, cx
0x13be8: js 0x13bee
2018-12-17T22:55:48.902286398Z 64 PC: 12e5f | Write file or device (Write 1056 bytes on handle 5)
2018-12-17T22:55:48.922498205Z 64 PC: 12e6b | Write file or device (Write 4545 bytes on handle 5)
2018-12-17T22:55:48.932634338Z 64 PC: 12e72 | Write file or device (Write 278 bytes on handle 5)
2018-12-17T22:55:48.937407513Z 62 PC: 12e76 | Close file
2018-12-17T22:55:48.94695036Z 51 PC: 12e7c | Get or set Ctrl-Break
2018-12-17T22:55:48.948028427Z 9 PC: 12af9 | Display string (Could not find end pointer)
2018-12-17T22:55:48.964800086Z 9 PC: 12af9 | Display string (String= ' ')