Sample viewer

vx.netlux.org/Virus.DOS.Vienna.645.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:08:21.406099409Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:08:21.408053934Z 47 PC: 12a6f | Get disk transfer address
2018-12-17T22:08:21.409148529Z 26 PC: 12a82 | Set disk transfer address
2018-12-17T22:08:21.410202095Z 78 PC: 12b0e | Find first file
2018-12-17T22:08:21.416114927Z 67 PC: 12b4c | Get or set file attributes
2018-12-17T22:08:21.422831062Z 67 PC: 12b5e | Get or set file attributes
2018-12-17T22:08:21.440920257Z 61 PC: 12b69 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:08:21.447366222Z 87 PC: 12b75 | Get or set file date and time
2018-12-17T22:08:21.448820047Z 44 PC: 12b81 | Get time 0x12b81: and dh, 7
0x12b84: jmp 0x12b96
0x12b86: mov ah, 0x40
0x12b88: mov cx, 5
0x12b8b: mov dx, si
0x12b8d: add dx, 0x8a
0x12b91: int 0x21
0x12b93: jmp 0x12bfa
0x12b95: nop
0x12b96: mov ah, 0x3f
0x12b98: mov cx, 3
0x12b9b: mov dx, 0xa
0x12b9e: nop
0x12b9f: add dx, si
0x12ba1: int 0x21
0x12ba3: jb 0x12bfa
0x12ba5: cmp ax, 3
0x12ba8: jne 0x12bfa
0x12baa: mov ax, 0x4202
0x12bad: mov cx, 0
2018-12-17T22:08:21.450139614Z 63 PC: 12ba3 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:08:21.453898026Z 66 PC: 12bb5 | Move file pointer
2018-12-17T22:08:21.455587054Z 64 PC: 12bd9 | Write file or device (Write 645 bytes on handle 5)
2018-12-17T22:08:21.461036629Z 66 PC: 12beb | Move file pointer
2018-12-17T22:08:21.462008499Z 64 PC: 12bfa | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:08:21.466540803Z 87 PC: 12c0d | Get or set file date and time
2018-12-17T22:08:21.467540786Z 62 PC: 12c11 | Close file
2018-12-17T22:08:21.472327568Z 67 PC: 12c20 | Get or set file attributes
2018-12-17T22:08:21.481777411Z 26 PC: 12c2d | Set disk transfer address
2018-12-17T22:08:21.482789451Z 0 PC: 12a4a | Program terminate