Sample viewer

vx.netlux.org/Virus.DOS.Birgit-based

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:36.079939837Z 250 PC: 12aa0 | UNKNOWN!
2018-12-17T22:59:36.082074688Z 42 PC: 12a85 | Get date 0x12a85: mov al, dl
0x12a87: cwde
0x12a88: cmp ax, 0x13
0x12a8b: jne 0x12aa1
0x12a8d: mov dx, 0x445
0x12a90: mov ah, 9
0x12a92: int 0x21
0x12a94: int 0x20
0x12a96: push 0xfa02
0x12a99: pop ax
0x12a9a: push 0x5945
0x12a9d: pop dx
0x12a9e: int 0x21
0x12aa0: ret
0x12aa1: cld
0x12aa2: mov cx, 4
0x12aa5: mov di, 0x100
0x12aa8: lea si, word ptr [bp + 0x370]
0x12aac: rep movsb byte ptr es:[di], byte ptr [si]
0x12aae: mov ah, 0x47
2018-12-17T22:59:36.085001188Z 71 PC: 12ab8 | Get current directory
2018-12-17T22:59:36.089178499Z 78 PC: 12ac3 | Find first file
2018-12-17T22:59:36.096601088Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.100216583Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.103122655Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.106038114Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.115593031Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.119138113Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.122471117Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.12600078Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.129286475Z 79 PC: 12b36 | Find next file
2018-12-17T22:59:36.131997841Z 59 PC: 12b20 | Change current directory
2018-12-17T22:59:36.138354317Z 59 PC: 12b5c | Change current directory
2018-12-17T22:59:36.142966775Z 250 PC: 12aa0 | UNKNOWN!
2018-12-17T22:59:36.144292457Z 76 PC: 12a4e | Terminate with return code (Return code = '0')