Sample viewer

vx.netlux.org/Virus.DOS.Vienna.500

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:30.897343888Z 37 PC: 12e38 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:30.899510459Z 26 PC: 12e4f | Set disk transfer address
2018-12-17T23:02:30.901347661Z 78 PC: 12ec9 | Find first file
2018-12-17T23:02:30.908661453Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.911501629Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.915606341Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.91904895Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.922553735Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.926827606Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.930063926Z 79 PC: 12ed0 | Find next file
2018-12-17T23:02:30.933265011Z 67 PC: 12f0e | Get or set file attributes
2018-12-17T23:02:30.940466662Z 67 PC: 12f1e | Get or set file attributes
2018-12-17T23:02:30.95956158Z 61 PC: 12f28 | Open file (Filename = 'TEST.COM')
2018-12-17T23:02:30.966955763Z 87 PC: 12f34 | Get or set file date and time
2018-12-17T23:02:30.968761315Z 63 PC: 12f43 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:02:30.972397928Z 66 PC: 12f53 | Move file pointer
2018-12-17T23:02:30.974689764Z 64 PC: 12ffc | Write file or device (Write 500 bytes on handle 5)
2018-12-17T23:02:30.990929296Z 66 PC: 12f82 | Move file pointer
2018-12-17T23:02:30.993970691Z 64 PC: 12f90 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:02:30.997560907Z 87 PC: 12fa1 | Get or set file date and time
2018-12-17T23:02:30.999919569Z 62 PC: 12fa5 | Close file
2018-12-17T23:02:31.010216185Z 67 PC: 12fad | Get or set file attributes
2018-12-17T23:02:31.015545979Z 42 PC: 12fb1 | Get date 0x12fb1: cmp dl, 0xd
0x12fb4: jne 0x12fba
0x12fb6: cmp al, 5
0x12fb8: je 0x12fbc
0x12fba: jmp 0x13004
0x12fbc: mov al, 2
0x12fbe: push ax
0x12fbf: xor dx, dx
0x12fc1: mov cx, 0x7f
0x12fc4: int 0x26
0x12fc6: popf
0x12fc7: pop ax
0x12fc8: cmp al, 3
0x12fca: je 0x12fba
0x12fcc: mov al, 3
0x12fce: jmp 0x12fbe
0x12fd0: push ax
0x12fd1: push bx
0x12fd2: push cx
0x12fd3: push dx
2018-12-17T23:02:31.01850582Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14242,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:10.722476894Z 37 PC: 12e38 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:40:10.727352718Z 26 PC: 12e4f | Set disk transfer address
2018-12-25T12:40:10.728995574Z 78 PC: 12ec9 | Find first file
2018-12-25T12:40:10.736029624Z 79 PC: 12ed0 | Find next file
2018-12-25T12:40:10.739193442Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.742363463Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.745338472Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.748159976Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.772624716Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.776260013Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.779184823Z 67 PC: 12f0e | Get or set file attributes
2018-12-25T12:40:10.786920326Z 67 PC: 12f1e | Get or set file attributes
2018-12-25T12:40:10.804455834Z 61 PC: 12f28 | Open file (Filename = 'TEST.COM')
2018-12-25T12:40:10.811869554Z 87 PC: 12f34 | Get or set file date and time
2018-12-25T12:40:10.814349512Z 63 PC: 12f43 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:40:10.817595518Z 66 PC: 12f53 | Move file pointer
2018-12-25T12:40:10.819825249Z 64 PC: 12ffc | Write file or device (Write 500 bytes on handle 5)
2018-12-25T12:40:10.829590099Z 66 PC: 12f82 | Move file pointer
2018-12-25T12:40:10.833363402Z 64 PC: 12f90 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:40:10.83756328Z 87 PC: 12fa1 | Get or set file date and time
2018-12-25T12:40:10.839460554Z 62 PC: 12fa5 | Close file
2018-12-25T12:40:10.848802204Z 67 PC: 12fad | Get or set file attributes
2018-12-25T12:40:10.855140134Z 42 PC: 12fb1 | Get date 0x12fb1: cmp dl, 0xd
0x12fb4: jne 0x12fba
0x12fb6: cmp al, 5
0x12fb8: je 0x12fbc
0x12fba: jmp 0x13004
0x12fbc: mov al, 2
0x12fbe: push ax
0x12fbf: xor dx, dx
0x12fc1: mov cx, 0x7f
0x12fc4: int 0x26
0x12fc6: popf
0x12fc7: pop ax
0x12fc8: cmp al, 3
0x12fca: je 0x12fba
0x12fcc: mov al, 3
0x12fce: jmp 0x12fbe
0x12fd0: push ax
0x12fd1: push bx
0x12fd2: push cx
0x12fd3: push dx
2018-12-25T12:40:10.857657715Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":13,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14242,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:10.677872834Z 37 PC: 12e38 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:40:10.679582589Z 26 PC: 12e4f | Set disk transfer address
2018-12-25T12:40:10.682773543Z 78 PC: 12ec9 | Find first file
2018-12-25T12:40:10.69026195Z 79 PC: 12ed0 | Find next file
2018-12-25T12:40:10.693343903Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.696552993Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.69937866Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.70214387Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.705831285Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.708555338Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:10.711338387Z 67 PC: 12f0e | Get or set file attributes
2018-12-25T12:40:10.718067502Z 67 PC: 12f1e | Get or set file attributes
2018-12-25T12:40:10.746571007Z 61 PC: 12f28 | Open file (Filename = 'TEST.COM')
2018-12-25T12:40:10.753341325Z 87 PC: 12f34 | Get or set file date and time
2018-12-25T12:40:10.755813531Z 63 PC: 12f43 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:40:10.758725933Z 66 PC: 12f53 | Move file pointer
2018-12-25T12:40:10.760560584Z 64 PC: 12ffc | Write file or device (Write 500 bytes on handle 5)
2018-12-25T12:40:10.775170603Z 66 PC: 12f82 | Move file pointer
2018-12-25T12:40:10.776731433Z 64 PC: 12f90 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:40:10.779913929Z 87 PC: 12fa1 | Get or set file date and time
2018-12-25T12:40:10.781754857Z 62 PC: 12fa5 | Close file
2018-12-25T12:40:10.78998275Z 67 PC: 12fad | Get or set file attributes
2018-12-25T12:40:10.796069431Z 42 PC: 12fb1 | Get date 0x12fb1: cmp dl, 0xd
0x12fb4: jne 0x12fba
0x12fb6: cmp al, 5
0x12fb8: je 0x12fbc
0x12fba: jmp 0x13004
0x12fbc: mov al, 2
0x12fbe: push ax
0x12fbf: xor dx, dx
0x12fc1: mov cx, 0x7f
0x12fc4: int 0x26
0x12fc6: popf
0x12fc7: pop ax
0x12fc8: cmp al, 3
0x12fca: je 0x12fba
0x12fcc: mov al, 3
0x12fce: jmp 0x12fbe
0x12fd0: push ax
0x12fd1: push bx
0x12fd2: push cx
0x12fd3: push dx
2018-12-25T12:40:10.798801921Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":13,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14242,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:11.186463206Z 37 PC: 12e38 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:40:11.18849626Z 26 PC: 12e4f | Set disk transfer address
2018-12-25T12:40:11.189701351Z 78 PC: 12ec9 | Find first file
2018-12-25T12:40:11.195565787Z 79 PC: 12ed0 | Find next file
2018-12-25T12:40:11.198729848Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:11.201239463Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:11.210480762Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:11.213490366Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:11.216007692Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:11.218505949Z 79 PC: 12ed0 | Find next file (See above)
2018-12-25T12:40:11.221800599Z 67 PC: 12f0e | Get or set file attributes
2018-12-25T12:40:11.228100428Z 67 PC: 12f1e | Get or set file attributes
2018-12-25T12:40:11.24373873Z 61 PC: 12f28 | Open file (Filename = 'TEST.COM')
2018-12-25T12:40:11.251428638Z 87 PC: 12f34 | Get or set file date and time
2018-12-25T12:40:11.252933897Z 63 PC: 12f43 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:40:11.255497823Z 66 PC: 12f53 | Move file pointer
2018-12-25T12:40:11.257143112Z 64 PC: 12ffc | Write file or device (Write 500 bytes on handle 5)
2018-12-25T12:40:11.265611245Z 66 PC: 12f82 | Move file pointer
2018-12-25T12:40:11.266990032Z 64 PC: 12f90 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:40:11.26968668Z 87 PC: 12fa1 | Get or set file date and time
2018-12-25T12:40:11.271853958Z 62 PC: 12fa5 | Close file
2018-12-25T12:40:11.279575939Z 67 PC: 12fad | Get or set file attributes
2018-12-25T12:40:11.285422848Z 42 PC: 12fb1 | Get date 0x12fb1: cmp dl, 0xd
0x12fb4: jne 0x12fba
0x12fb6: cmp al, 5
0x12fb8: je 0x12fbc
0x12fba: jmp 0x13004
0x12fbc: mov al, 2
0x12fbe: push ax
0x12fbf: xor dx, dx
0x12fc1: mov cx, 0x7f
0x12fc4: int 0x26
0x12fc6: popf
0x12fc7: pop ax
0x12fc8: cmp al, 3
0x12fca: je 0x12fba
0x12fcc: mov al, 3
0x12fce: jmp 0x12fbe
0x12fd0: push ax
0x12fd1: push bx
0x12fd2: push cx
0x12fd3: push dx
2018-12-25T12:40:11.288926755Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')