Sample viewer

vx.netlux.org/Trojan.DOS.Diga.255

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:39.788752916Z 78 PC: 12a91 | Find first file
2018-12-17T22:51:39.794663305Z 61 PC: 12a91 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:51:39.800868731Z 64 PC: 12a91 | Write file or device (Write 0 bytes on handle 2)
2018-12-17T22:51:39.802441372Z 62 PC: 12a91 | Close file
2018-12-17T22:51:39.804410524Z 79 PC: 12a91 | Find next file
2018-12-17T22:51:39.812473952Z 42 PC: 12a91 | Get date 0x12a91: ret
0x12a92: or ax, 0x440a
0x12a95: imul sp, word ptr [bx + 0x61], 0x4e20
0x12a9a: inc cx
0x12a9b: dec di
0x12a9c: and byte ptr [bx + di + 0x20], ah
0x12a9f: jo 0x12b10
0x12aa1: jb 0x12b11
0x12aa3: outsw dx, word ptr [si]
0x12aa4: jb 0x12b08
0x12aa7: imul esp, dword ptr [bx + di + 0x20], 0x61666e69
0x12aaf: outsb dx, byte ptr [si]
0x12ab0: je 0x12b1b
0x12ab2: insb byte ptr es:[di], dx
0x12ab3: and byte ptr cs:[di], cl
0x12ab9: or dl, byte ptr [bp + di + 0x61]
0x12abc: jns 0x12ade
0x12abe: dec si
0x12abf: dec di
0x12ac0: and byte ptr [si + 0x6f], dh
2018-12-17T22:51:39.814904435Z 42 PC: 12a91 | Get date 0x12a91: ret
0x12a92: or ax, 0x440a
0x12a95: imul sp, word ptr [bx + 0x61], 0x4e20
0x12a9a: inc cx
0x12a9b: dec di
0x12a9c: and byte ptr [bx + di + 0x20], ah
0x12a9f: jo 0x12b10
0x12aa1: jb 0x12b11
0x12aa3: outsw dx, word ptr [si]
0x12aa4: jb 0x12b08
0x12aa7: imul esp, dword ptr [bx + di + 0x20], 0x61666e69
0x12aaf: outsb dx, byte ptr [si]
0x12ab0: je 0x12b1b
0x12ab2: insb byte ptr es:[di], dx
0x12ab3: and byte ptr cs:[di], cl
0x12ab9: or dl, byte ptr [bp + di + 0x61]
0x12abc: jns 0x12ade
0x12abe: dec si
0x12abf: dec di
0x12ac0: and byte ptr [si + 0x6f], dh