Sample viewer

vx.netlux.org/Virus.DOS.Vienna.764

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:29.821079556Z 42 PC: 12bb5 | Get date 0x12bb5: cmp dl, byte ptr [si + 0xdb]
0x12bb9: jne 0x12bbe
0x12bbb: jmp 0x12c56
0x12bbe: mov byte ptr [si + 0xdb], dl
0x12bc2: mov al, byte ptr [si + 0xb8]
0x12bc6: dec al
0x12bc8: mov byte ptr [si + 0xb8], al
0x12bcc: jne 0x12be2
0x12bce: mov ah, 9
0x12bd0: mov dx, si
0x12bd2: add dx, 8
0x12bd5: int 0x15
0x12bd7: mov ah, 1
0x12bd9: int 0x15
0x12bdb: cmp word ptr [si + 0xcc], 0
0x12be0: je 0x12bbb
0x12be2: mov ah, 0x3f
0x12be4: mov cx, 4
0x12be7: mov dx, 0xb9
0x12bea: add dx, si
2018-12-17T23:04:29.824743898Z 62 PC: 12c56 | Close file
2018-12-17T23:04:29.827147289Z 37 PC: 12c78 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:29.829128445Z 0 PC: 12a4a | Program terminate