Sample viewer

vx.netlux.org/Virus.DOS.Viva.748

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:25.198003451Z 37 PC: 12a6f | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:08:25.200424472Z 53 PC: 12a76 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:25.202064937Z 2 PC: 12ce9 | Character output (Char = '00')
2018-12-17T23:08:25.204654183Z 2 PC: 12ce9 | Character output (Char = '08')
2018-12-17T23:08:25.207342099Z 71 PC: 12ce9 | Get current directory
2018-12-17T23:08:25.217119734Z 26 PC: 12ce9 | Set disk transfer address
2018-12-17T23:08:25.218403101Z 53 PC: 12ce9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:25.219801668Z 37 PC: 12ce9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:25.222358886Z 78 PC: 12ce9 | Find first file
2018-12-17T23:08:25.229118697Z 61 PC: 12ce9 | Open file (Filename = 'TEST.EXE')
2018-12-17T23:08:25.236503744Z 63 PC: 12ce9 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:08:25.246374867Z 62 PC: 12ce9 | Close file
2018-12-17T23:08:25.24881839Z 79 PC: 12ce9 | Find next file
2018-12-17T23:08:25.251759954Z 59 PC: 12ce9 | Change current directory
2018-12-17T23:08:25.258558532Z 59 PC: 12ce9 | Change current directory
2018-12-17T23:08:25.273134738Z 44 PC: 12ce9 | Get time 0x12ce9: ret
0x12cea: ljmp 0x19:0x40f8
0x12cef: add byte ptr [bx + di], al
2018-12-17T23:08:25.276306149Z 37 PC: 12ce9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:25.27843868Z 59 PC: 12ce9 | Change current directory
2018-12-17T23:08:25.283774721Z 26 PC: 12ce9 | Set disk transfer address