Sample viewer

vx.netlux.org/Virus.DOS.Vienna.822

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:45.978066894Z 48 PC: 12e41 | Get DOS version
2018-12-17T22:24:45.980861165Z 47 PC: 12e4d | Get disk transfer address
2018-12-17T22:24:45.993827056Z 26 PC: 12e63 | Set disk transfer address
2018-12-17T22:24:45.996051286Z 78 PC: 12eef | Find first file
2018-12-17T22:24:46.004607278Z 67 PC: 12f2d | Get or set file attributes
2018-12-17T22:24:46.010427796Z 67 PC: 12f40 | Get or set file attributes
2018-12-17T22:24:46.033706365Z 61 PC: 12f4b | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:24:46.040583096Z 87 PC: 12f57 | Get or set file date and time
2018-12-17T22:24:46.042237889Z 44 PC: 12f63 | Get time 0x12f63: and dh, 7
0x12f66: jmp 0x12f75
0x12f68: nop
0x12f69: mov ah, 0x40
0x12f6b: mov cx, 5
0x12f6e: mov dx, si
0x12f70: add dx, 0x8a
0x12f74: nop
0x12f75: mov ah, 0x3f
0x12f77: mov cx, 3
0x12f7a: mov dx, 0xa
0x12f7d: nop
0x12f7e: add dx, si
0x12f80: int 0x21
0x12f82: jb 0x12fd9
0x12f84: cmp ax, 3
0x12f87: jne 0x12fd9
0x12f89: mov ax, 0x4202
0x12f8c: mov cx, 0
0x12f8f: mov dx, 0
2018-12-17T22:24:46.044703898Z 63 PC: 12f82 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:24:46.05126403Z 66 PC: 12f94 | Move file pointer
2018-12-17T22:24:46.053993951Z 64 PC: 12fb8 | Write file or device (Write 822 bytes on handle 5)
2018-12-17T22:24:46.062330788Z 66 PC: 12fca | Move file pointer
2018-12-17T22:24:46.064362897Z 64 PC: 12fd9 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:24:46.071418335Z 87 PC: 12fee | Get or set file date and time
2018-12-17T22:24:46.073177391Z 62 PC: 12ff2 | Close file
2018-12-17T22:24:46.08105331Z 67 PC: 13001 | Get or set file attributes
2018-12-17T22:24:46.09700254Z 26 PC: 1300e | Set disk transfer address