Sample viewer

vx.netlux.org/Trojan.DOS.SPS.104

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:29.053695246Z 44 PC: 12a69 | Get time 0x12a69: jno 0x12a6f
0x12a6b: add di, 0x3f03
0x12a6f: cmp cx, 0x3e
0x12a73: mov ch, 0x25
0x12a76: jae 0x12a7c
0x12a78: rcl ch, 1
0x12a7a: shl ch, 1
0x12a7c: add di, 0x1f2c
0x12a80: sub ch, 0x23
0x12a83: cmp ch, bh
0x12a85: sub cl, byte ptr [bx + si + 0x10]
0x12a88: neg ch
0x12a8a: shl bp, 1
0x12a8c: xor ch, 0x36
0x12a8f: rol ch, 1
0x12a91: and bp, 0x3a12
0x12a95: test cl, 0x1e
0x12a98: not cx
0x12a9a: shr cl, 1
0x12a9c: test byte ptr [bx + di], dh
2018-12-17T23:03:29.065991522Z 52 PC: 12a6d | Get InDOS flag pointer
2018-12-17T23:03:29.06801506Z 81 PC: 12a75 | Get current PSP
2018-12-17T23:03:29.069730711Z 9 PC: 12b31 | Display string (String= ' PasswordCracker 1.04 4 Novell Network. (c) 1997 by Psychomancer aka Nice,SPS.')
2018-12-17T23:03:29.077418784Z 9 PC: 12b31 | Display string (String= ' ')
2018-12-17T23:03:29.088091467Z 37 PC: 12aa8 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:29.089447749Z 37 PC: 12aae | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:29.090970918Z 51 PC: 12e3b | Get or set Ctrl-Break
2018-12-17T23:03:29.09335091Z 51 PC: 12ecc | Get or set Ctrl-Break
2018-12-17T23:03:29.094975323Z 9 PC: 12b31 | Display string (Could not find end pointer)
2018-12-17T23:03:29.127020378Z 9 PC: 12b31 | Display string (String= ' ')