Sample viewer

vx.netlux.org/Trojan.DOS.DarkVoid

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:38.595993222Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:48:38.598310696Z 53 PC: 12bef | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:38.600012304Z 53 PC: 12bfc | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:48:38.60148991Z 53 PC: 12c09 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:48:38.603141233Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:48:38.604714308Z 37 PC: 12c2a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:48:38.606394806Z 74 PC: 12af4 | Reallocate memory
2018-12-17T22:48:38.609240743Z 68 PC: 13003 | I/O control for devices (Set for = 'pyright 1991 Borland Intl.')
2018-12-17T22:48:38.611827834Z 68 PC: 13003 | I/O control for devices (Set for = '')
2018-12-17T22:48:38.615046252Z 42 PC: 12e70 | Get date 0x12e70: mov word ptr [si], cx
0x12e72: mov word ptr [si + 2], dx
0x12e75: pop si
0x12e76: pop bp
0x12e77: ret
0x12e78: push bp
0x12e79: mov bp, sp
0x12e7b: push si
0x12e7c: mov si, word ptr [bp + 4]
0x12e7f: mov ah, 0x2c
0x12e81: int 0x21
0x12e83: mov word ptr [si], cx
0x12e85: mov word ptr [si + 2], dx
0x12e88: pop si
0x12e89: pop bp
0x12e8a: ret
0x12e8b: push bp
0x12e8c: mov bp, sp
0x12e8e: push word ptr [bp + 4]
0x12e91: mov al, 0
2018-12-17T22:48:38.617773857Z 44 PC: 12e83 | Get time 0x12e83: mov word ptr [si], cx
0x12e85: mov word ptr [si + 2], dx
0x12e88: pop si
0x12e89: pop bp
0x12e8a: ret
0x12e8b: push bp
0x12e8c: mov bp, sp
0x12e8e: push word ptr [bp + 4]
0x12e91: mov al, 0
0x12e93: push ax
0x12e94: call 0x12e9b
0x12e97: pop cx
0x12e98: pop cx
0x12e99: pop bp
0x12e9a: ret
0x12e9b: push bp
0x12e9c: mov bp, sp
0x12e9e: push si
0x12e9f: mov si, word ptr [bp + 6]
0x12ea2: push ds
2018-12-17T22:48:38.627794395Z 64 PC: 149bb | Write file or device (Write 34 bytes on handle 1)
2018-12-17T22:48:38.636165223Z 64 PC: 149bb | Write file or device (Write 11 bytes on handle 1)
2018-12-17T22:48:38.643783457Z 64 PC: 149bb | Write file or device (Write 14 bytes on handle 1)
2018-12-17T22:48:38.652652131Z 28 PC: 12eaa | Get allocation info for specified drive
2018-12-17T22:48:38.704499639Z 53 PC: 12ee9 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:48:38.705946769Z 37 PC: 12efc | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:48:38.708783178Z 73 PC: 12daa | Release memory
2018-12-17T22:48:38.710344962Z 49 PC: 12db4 | Terminate and stay resident (Return code = '0' | Memory size = '4756')