Sample viewer

vx.netlux.org/Virus.DOS.Vienna.ByteWarrior.1214

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:41.214359331Z 48 PC: 151af | Get DOS version
2018-12-17T23:07:41.215936406Z 47 PC: 151bc | Get disk transfer address
2018-12-17T23:07:41.217185348Z 26 PC: 151cb | Set disk transfer address
2018-12-17T23:07:41.218365131Z 78 PC: 15256 | Find first file
2018-12-17T23:07:41.22473017Z 79 PC: 15260 | Find next file
2018-12-17T23:07:41.227610856Z 79 PC: 15260 | Find next file
2018-12-17T23:07:41.230449858Z 79 PC: 15260 | Find next file
2018-12-17T23:07:41.234729367Z 79 PC: 15260 | Find next file
2018-12-17T23:07:41.238235146Z 79 PC: 15260 | Find next file
2018-12-17T23:07:41.241091883Z 67 PC: 152b5 | Get or set file attributes
2018-12-17T23:07:41.246766624Z 67 PC: 152c5 | Get or set file attributes
2018-12-17T23:07:41.262433017Z 61 PC: 152cf | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:07:41.268741191Z 87 PC: 152de | Get or set file date and time
2018-12-17T23:07:41.270083404Z 44 PC: 152e8 | Get time 0x152e8: mov cx, 3
0x152eb: mov ah, 0x3f
0x152ed: mov dx, 0xa
0x152f0: add dx, si
0x152f2: push dx
0x152f3: int 0x21
0x152f5: pop bp
0x152f6: jb 0x1531c
0x152f8: cmp byte ptr [bp], 0x4d
0x152fc: jne 0x1530a
0x152fe: cmp byte ptr [bp + 1], 0x5a
0x15302: je 0x1531c
0x15304: jmp 0x1530a
0x15306: jmp 0x1535c
0x15308: jmp 0x1535a
0x1530a: cmp ax, 3
0x1530d: jne 0x1535e
0x1530f: xor cx, cx
0x15311: mov ax, 0x4202
0x15314: xor dx, dx
2018-12-17T23:07:41.273049674Z 63 PC: 152f5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:07:41.279321433Z 66 PC: 15318 | Move file pointer
2018-12-17T23:07:41.280869454Z 64 PC: 15375 | Write file or device (Write 1227 bytes on handle 5)
2018-12-17T23:07:41.290066084Z 66 PC: 15385 | Move file pointer
2018-12-17T23:07:41.291325123Z 64 PC: 15393 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:07:41.29754371Z 87 PC: 153a4 | Get or set file date and time
2018-12-17T23:07:41.299237803Z 62 PC: 153a8 | Close file
2018-12-17T23:07:41.30723587Z 67 PC: 153b5 | Get or set file attributes
2018-12-17T23:07:41.316679455Z 26 PC: 153bf | Set disk transfer address
2018-12-17T23:07:41.318534074Z 26 PC: 1541f | Set disk transfer address
2018-12-17T23:07:41.322147563Z 9 PC: 12a5d | Display string (String= '')
2018-12-17T23:07:41.324058297Z 9 PC: 12a64 | Display string (Could not find end pointer)
2018-12-17T23:07:41.334869117Z 76 PC: 12a7a | Terminate with return code (Return code = '0')