Sample viewer

vx.netlux.org/Virus.DOS.Vienna.960

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:16.607351705Z 47 PC: 12e81 | Get disk transfer address
2018-12-17T23:11:16.609406259Z 26 PC: 12e90 | Set disk transfer address
2018-12-17T23:11:16.611846649Z 78 PC: 12f19 | Find first file
2018-12-17T23:11:16.618818963Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.621866595Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.62600535Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.628984203Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.631915896Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.635728247Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.639768616Z 79 PC: 12f24 | Find next file
2018-12-17T23:11:16.643026554Z 67 PC: 12f79 | Get or set file attributes
2018-12-17T23:11:16.650380245Z 67 PC: 12f89 | Get or set file attributes
2018-12-17T23:11:16.667996468Z 61 PC: 12f93 | Open file (Filename = 'TEST.COM')
2018-12-17T23:11:16.675816687Z 87 PC: 12fa2 | Get or set file date and time
2018-12-17T23:11:16.678891219Z 44 PC: 12fac | Get time 0x12fac: mov cx, 3
0x12faf: mov ah, 0x3f
0x12fb1: mov dx, 0xa
0x12fb4: add dx, si
0x12fb6: push dx
0x12fb7: int 0x21
0x12fb9: pop bp
0x12fba: jb 0x12fe0
0x12fbc: cmp byte ptr [bp], 0x4d
0x12fc0: jne 0x12fce
0x12fc2: cmp byte ptr [bp + 1], 0x5a
0x12fc6: je 0x12fe0
0x12fc8: jmp 0x12fce
0x12fca: jmp 0x13020
0x12fcc: jmp 0x1301e
0x12fce: cmp ax, 3
0x12fd1: jne 0x13022
0x12fd3: xor cx, cx
0x12fd5: mov ax, 0x4202
0x12fd8: xor dx, dx
2018-12-17T23:11:16.681658043Z 63 PC: 12fb9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:16.68480392Z 66 PC: 12fdc | Move file pointer
2018-12-17T23:11:16.687323329Z 64 PC: 13039 | Write file or device (Write 960 bytes on handle 5)
2018-12-17T23:11:16.697145483Z 66 PC: 13049 | Move file pointer
2018-12-17T23:11:16.699042511Z 64 PC: 13057 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:11:16.70239171Z 87 PC: 13065 | Get or set file date and time
2018-12-17T23:11:16.706347099Z 62 PC: 13069 | Close file
2018-12-17T23:11:16.720113081Z 67 PC: 13076 | Get or set file attributes
2018-12-17T23:11:16.731693962Z 26 PC: 13080 | Set disk transfer address
2018-12-17T23:11:16.734075452Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:11:16.738451311Z 76 PC: 12a86 | Terminate with return code (Return code = '36')