Sample viewer

vx.netlux.org/Trojan.DOS.Diga.253

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:33.032503078Z 78 PC: 12a8f | Find first file
2018-12-17T23:06:33.036488554Z 61 PC: 12a8f | Open file (Filename = 'COMMAND.COM')
2018-12-17T23:06:33.04149166Z 64 PC: 12a8f | Write file or device (Write 253 bytes on handle 2)
2018-12-17T23:06:33.047559676Z 62 PC: 12a8f | Close file
2018-12-17T23:06:33.048861837Z 79 PC: 12a8f | Find next file
2018-12-17T23:06:33.051870433Z 42 PC: 12a8f | Get date 0x12a8f: ret
0x12a90: or ax, 0x440a
0x12a93: imul sp, word ptr [bx + 0x61], 0x4e20
0x12a98: inc cx
0x12a99: dec di
0x12a9a: and byte ptr [bx + di + 0x20], ah
0x12a9d: jo 0x12b0e
0x12a9f: jb 0x12b0f
0x12aa1: outsw dx, word ptr [si]
0x12aa2: jb 0x12b06
0x12aa5: imul esp, dword ptr [bx + di + 0x20], 0x61666e69
0x12aad: outsb dx, byte ptr [si]
0x12aae: je 0x12b19
0x12ab0: insb byte ptr es:[di], dx
0x12ab1: and byte ptr cs:[di], cl
0x12ab7: or dl, byte ptr [bp + di + 0x61]
0x12aba: jns 0x12adc
0x12abc: dec si
0x12abd: dec di
0x12abe: and byte ptr [si + 0x6f], dh
2018-12-17T23:06:33.055438203Z 42 PC: 12a8f | Get date 0x12a8f: ret
0x12a90: or ax, 0x440a
0x12a93: imul sp, word ptr [bx + 0x61], 0x4e20
0x12a98: inc cx
0x12a99: dec di
0x12a9a: and byte ptr [bx + di + 0x20], ah
0x12a9d: jo 0x12b0e
0x12a9f: jb 0x12b0f
0x12aa1: outsw dx, word ptr [si]
0x12aa2: jb 0x12b06
0x12aa5: imul esp, dword ptr [bx + di + 0x20], 0x61666e69
0x12aad: outsb dx, byte ptr [si]
0x12aae: je 0x12b19
0x12ab0: insb byte ptr es:[di], dx
0x12ab1: and byte ptr cs:[di], cl
0x12ab7: or dl, byte ptr [bp + di + 0x61]
0x12aba: jns 0x12adc
0x12abc: dec si
0x12abd: dec di
0x12abe: and byte ptr [si + 0x6f], dh