Sample viewer

vx.netlux.org/Virus.DOS.Vienna.ByteWarrior.1155.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:03.740063804Z 48 PC: 1367a | Get DOS version
2018-12-17T22:56:03.741778448Z 47 PC: 13687 | Get disk transfer address
2018-12-17T22:56:03.744251538Z 26 PC: 13696 | Set disk transfer address
2018-12-17T22:56:03.745806693Z 78 PC: 13721 | Find first file
2018-12-17T22:56:03.753929228Z 79 PC: 1372c | Find next file
2018-12-17T22:56:03.75790811Z 79 PC: 1372c | Find next file
2018-12-17T22:56:03.761295419Z 79 PC: 1372c | Find next file
2018-12-17T22:56:03.76409823Z 79 PC: 1372c | Find next file
2018-12-17T22:56:03.767501009Z 79 PC: 1372c | Find next file
2018-12-17T22:56:03.770363341Z 67 PC: 13781 | Get or set file attributes
2018-12-17T22:56:03.776248227Z 67 PC: 13791 | Get or set file attributes
2018-12-17T22:56:03.795012583Z 61 PC: 1379b | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:03.801995184Z 87 PC: 137aa | Get or set file date and time
2018-12-17T22:56:03.803399404Z 44 PC: 137b4 | Get time 0x137b4: mov cx, 3
0x137b7: mov ah, 0x3f
0x137b9: mov dx, 0xa
0x137bc: add dx, si
0x137be: push dx
0x137bf: int 0x21
0x137c1: pop bp
0x137c2: jb 0x137e8
0x137c4: cmp byte ptr [bp], 0x4d
0x137c8: jne 0x137d6
0x137ca: cmp byte ptr [bp + 1], 0x5a
0x137ce: je 0x137e8
0x137d0: jmp 0x137d6
0x137d2: jmp 0x13828
0x137d4: jmp 0x13826
0x137d6: cmp ax, 3
0x137d9: jne 0x1382a
0x137db: xor cx, cx
0x137dd: mov ax, 0x4202
0x137e0: xor dx, dx
2018-12-17T22:56:03.806648664Z 63 PC: 137c1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:03.814134993Z 66 PC: 137e4 | Move file pointer
2018-12-17T22:56:03.816109706Z 64 PC: 13841 | Write file or device (Write 1214 bytes on handle 5)
2018-12-17T22:56:03.825282736Z 66 PC: 13851 | Move file pointer
2018-12-17T22:56:03.827345344Z 64 PC: 1385f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:03.83445296Z 87 PC: 13870 | Get or set file date and time
2018-12-17T22:56:03.836679917Z 62 PC: 13874 | Close file
2018-12-17T22:56:03.845090714Z 67 PC: 13881 | Get or set file attributes
2018-12-17T22:56:03.856283071Z 26 PC: 1388b | Set disk transfer address
2018-12-17T22:56:03.857785516Z 26 PC: 138eb | Set disk transfer address
2018-12-17T22:56:03.859847103Z 9 PC: 12a4b | Display string (String= 'Refresh v1.0 ')
2018-12-17T22:56:03.86614726Z 76 PC: 12a51 | Terminate with return code (Return code = '36')