Sample viewer

vx.netlux.org/Trojan.DOS.Darkness

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:56:54.722075706Z 48 PC: 12a4c | Get DOS version
2018-12-17T21:56:54.723713816Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:56:54.724820337Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:56:54.725868894Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:56:54.727544894Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:56:54.728648551Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:56:54.72997833Z 74 PC: 12af4 | Reallocate memory
2018-12-17T21:56:54.732587997Z 68 PC: 12f74 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T21:56:54.734773345Z 68 PC: 12f74 | I/O control for devices (Set for = '')
2018-12-17T21:56:54.737207873Z 42 PC: 12e01 | Get date 0x12e01: mov word ptr [si], cx
0x12e03: mov word ptr [si + 2], dx
0x12e06: pop si
0x12e07: pop bp
0x12e08: ret
0x12e09: push bp
0x12e0a: mov bp, sp
0x12e0c: push si
0x12e0d: mov si, word ptr [bp + 4]
0x12e10: mov ah, 0x2c
0x12e12: int 0x21
0x12e14: mov word ptr [si], cx
0x12e16: mov word ptr [si + 2], dx
0x12e19: pop si
0x12e1a: pop bp
0x12e1b: ret
0x12e1c: push bp
0x12e1d: mov bp, sp
0x12e1f: push word ptr [bp + 4]
0x12e22: mov al, 0
2018-12-17T21:56:54.739645575Z 44 PC: 12e14 | Get time 0x12e14: mov word ptr [si], cx
0x12e16: mov word ptr [si + 2], dx
0x12e19: pop si
0x12e1a: pop bp
0x12e1b: ret
0x12e1c: push bp
0x12e1d: mov bp, sp
0x12e1f: push word ptr [bp + 4]
0x12e22: mov al, 0
0x12e24: push ax
0x12e25: call 0x12e2c
0x12e28: pop cx
0x12e29: pop cx
0x12e2a: pop bp
0x12e2b: ret
0x12e2c: push bp
0x12e2d: mov bp, sp
0x12e2f: push si
0x12e30: mov si, word ptr [bp + 6]
0x12e33: push ds
2018-12-17T21:56:54.743423624Z 64 PC: 1488f | Write file or device (Write 27 bytes on handle 1)
2018-12-17T21:56:54.747182564Z 28 PC: 12e3b | Get allocation info for specified drive
2018-12-17T21:56:54.788246079Z 37 PC: 12c36 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:56:54.790561106Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:56:54.7919896Z 37 PC: 12c4c | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:56:54.793428311Z 37 PC: 12c57 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:56:54.795987156Z 76 PC: 12be0 | Terminate with return code (Return code = '3')