Sample viewer

vx.netlux.org/Virus.DOS.Vienna.776

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:51.040129643Z 26 PC: 12e42 | Set disk transfer address
2018-12-17T23:11:51.042316125Z 53 PC: 12e48 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:51.043949457Z 37 PC: 12e5c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:51.045633183Z 78 PC: 12ee0 | Find first file
2018-12-17T23:11:51.052258974Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.055946087Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.059063169Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.062097075Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.076217069Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.079304175Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.082270062Z 79 PC: 12ee6 | Find next file
2018-12-17T23:11:51.088793701Z 67 PC: 12f43 | Get or set file attributes
2018-12-17T23:11:51.094924851Z 67 PC: 12f54 | Get or set file attributes
2018-12-17T23:11:51.112480687Z 61 PC: 12f60 | Open file (Filename = 'TEST.COM')
2018-12-17T23:11:51.122071854Z 87 PC: 12f6c | Get or set file date and time
2018-12-17T23:11:51.12414909Z 42 PC: 12f78 | Get date 0x12f78: cmp dl, byte ptr [si + 0xdc]
0x12f7c: jne 0x12f81
0x12f7e: jmp 0x1301c
0x12f81: mov byte ptr [si + 0xdc], dl
0x12f85: mov al, byte ptr [si + 0xb9]
0x12f89: dec al
0x12f8b: mov byte ptr [si + 0xb9], al
0x12f8f: jne 0x12fa6
0x12f91: mov ah, 9
0x12f93: mov dx, si
0x12f95: add dx, 8
0x12f98: nop
0x12f99: int 0x21
0x12f9b: mov ah, 1
0x12f9d: int 0x21
0x12f9f: cmp word ptr [si + 0xcd], 0
0x12fa4: je 0x12f7e
0x12fa6: mov ah, 0x3f
0x12fa8: mov cx, 4
0x12fab: mov dx, 0xba
2018-12-17T23:11:51.127634946Z 63 PC: 12fb2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:11:51.131770122Z 66 PC: 12fc2 | Move file pointer
2018-12-17T23:11:51.1333218Z 64 PC: 12fe6 | Write file or device (Write 776 bytes on handle 5)
2018-12-17T23:11:51.141995012Z 66 PC: 12ff6 | Move file pointer
2018-12-17T23:11:51.143490945Z 64 PC: 13005 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:11:51.147445541Z 87 PC: 13018 | Get or set file date and time
2018-12-17T23:11:51.149334794Z 62 PC: 1301c | Close file
2018-12-17T23:11:51.158003346Z 67 PC: 1302a | Get or set file attributes
2018-12-17T23:11:51.17081513Z 26 PC: 13032 | Set disk transfer address
2018-12-17T23:11:51.172163306Z 37 PC: 13041 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')